High severity7.5NVD Advisory· Published Dec 23, 2022· Updated Jun 17, 2026
CVE-2022-23854
CVE-2022-23854
Description
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:aveva:intouch_access_anywhere:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:aveva:intouch_access_anywhere:*:*:*:*:*:*:*:*range: <2020
- cpe:2.3:a:aveva:intouch_access_anywhere:2020:-:*:*:*:*:*:*
- cpe:2.3:a:aveva:intouch_access_anywhere:2020:r2:*:*:*:*:*:*
<=2020 R2+ 1 more
- (no CPE)range: <=2020 R2
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.