Vulnerabilities (CVE)

Filtered by vendor Aveva Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-42794 1 Aveva 1 Edge 2023-12-20 N/A 5.3 MEDIUM
An issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a client to provide a malicious connection string that could allow an adversary to port scan the LAN, depending on the hosts' responses.
CVE-2017-5160 1 Aveva 1 Wonderware Intouch Access Anywhere 2021-08-31 3.5 LOW 5.3 MEDIUM
An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The software will connect via Transport Layer Security without verifying the peer's SSL certificate properly.
CVE-2021-32942 1 Aveva 2 Intouch 2017, Intouch 2020 2021-06-21 2.1 LOW 5.5 MEDIUM
The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location.