Medium severity5.3NVD Advisory· Published Dec 16, 2023· Updated Jun 17, 2026
CVE-2021-42794
CVE-2021-42794
Description
An issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a client to provide a malicious connection string that could allow an adversary to port scan the LAN, depending on the hosts' responses.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- AVEVA Edge/AVEVA Edgedescription
- Range: <=R2020
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/docs/english/17254-connection-string-parameter-pollution-attacks.pdfnvdExploitThird Party AdvisoryVDB Entry
- www.cisa.gov/news-events/ics-advisories/icsa-22-326-01nvdThird Party AdvisoryUS Government Resource
- www.aveva.com/en/products/edge/nvdProduct
News mentions
0No linked articles in our index yet.