VYPR
High severity7.5NVD Advisory· Published Dec 16, 2023· Updated Jun 17, 2026

CVE-2021-42797

CVE-2021-42797

Description

Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • Aveva/Edge5 versions
    cpe:2.3:a:aveva:edge:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:aveva:edge:*:*:*:*:*:*:*:*range: <2020
    • cpe:2.3:a:aveva:edge:2020:-:*:*:*:*:*:*
    • cpe:2.3:a:aveva:edge:2020:r2:-:*:*:*:*:*
    • cpe:2.3:a:aveva:edge:2020:r2:sp1:*:*:*:*:*
    • (no CPE)range: <=R2020
  • AVEVA Edge/AVEVA Edgedescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.