High severity7.5NVD Advisory· Published Dec 16, 2023· Updated Jun 17, 2026
CVE-2021-42797
CVE-2021-42797
Description
Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- AVEVA Edge/AVEVA Edgedescription
Patches
Vulnerability mechanics
References
2- www.cisa.gov/news-events/ics-advisories/icsa-22-326-01nvdThird Party AdvisoryUS Government Resource
- www.aveva.com/en/products/edge/nvdProduct
News mentions
0No linked articles in our index yet.