Lucene search

K
cve[email protected]CVE-2022-23854
HistoryDec 23, 2022 - 9:15 p.m.

CVE-2022-23854

2022-12-2321:15:09
CWE-22
CWE-23
web.nvd.nist.gov
40
cve-2022-23854
aveva intouch
access anywhere
path traversal
exploit
vulnerability
security
nvd

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

High

0.77 High

EPSS

Percentile

98.2%

AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server.

Affected configurations

NVD
Node
avevaintouch_access_anywhereRange<2020
OR
avevaintouch_access_anywhereMatch2020-
OR
avevaintouch_access_anywhereMatch2020r2

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "InTouch Access Anywhere",
    "vendor": "AVEVA",
    "versions": [
      {
        "lessThanOrEqual": "2020 R2",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

High

0.77 High

EPSS

Percentile

98.2%