Skip to content
Noroxi

AVEVA records

71 published records for vendor aveva.

All records

71 records
  • AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user

    HighCVSS 7.5Proof of conceptEPSS 46%

    aveva · intouch access anywhereDec 23, 2022

  • AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20

    CriticalCVSS 9.8Proof of conceptEPSS 17%

    aveva · indusoft web studioFeb 12, 2019

  • Use-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and

    CriticalCVSS 10.0No exploitEPSS 8%

    aveva · clearscadaAug 16, 2011

  • AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthenticated user to send a

    CriticalCVSS 9.8No exploitEPSS 5%

    aveva · intouch 2014Jul 24, 2018

  • InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.

    CriticalCVSS 9.8No exploitEPSS 5%

    aveva · indusoft web studioNov 2, 2018

  • AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully cra

    CriticalCVSS 9.8No exploitEPSS 4%

    aveva · indusoft web studioJul 19, 2018

  • InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.

    CriticalCVSS 9.8No exploitEPSS 4%

    aveva · indusoft web studioNov 2, 2018

  • An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.

    CriticalCVSS 9.8No exploitEPSS 3%

    aveva · edna enterprise data historianSep 24, 2020

  • SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.

    CriticalCVSS 9.8No exploitEPSS 3%

    aveva · edna enterprise data historianSep 24, 2020

  • An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.

    CriticalCVSS 9.8No exploitEPSS 3%

    aveva · edna enterprise data historianSep 24, 2020

  • An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior.

    CriticalCVSS 9.8No exploitEPSS 2%

    aveva · wonderware intouch access anywhereApr 20, 2017

  • AVEVA Process Optimization Code Injection

    CriticalCVSS 10.0No exploitEPSS 2%

    aveva · process optimizationJan 15, 2026

  • Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks.

    CriticalCVSS 9.8No exploitEPSS 1%

    aveva · edna enterprise data historianSep 24, 2020

  • Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks.

    CriticalCVSS 9.8No exploitEPSS 1%

    aveva · edna enterprise data historianSep 24, 2020

  • AVEVA System Platform Missing Authentication for Critical Function

    CriticalCVSS 9.8No exploitEPSS 1%

    aveva · system platformApr 4, 2022

  • An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticate

    CriticalCVSS 9.8No exploitEPSS 1%

    aveva · edgeDec 15, 2023

  • CVE-2022-1467
    39Monitor

    AVEVA InTouch Access Anywhere Exposure of Resource to Wrong Sphere

    CriticalCVSS 9.9No exploitEPSS 1%

    aveva · intouch access anywhereMay 23, 2022

  • AVEVA SuiteLink Server Buffer Overflow

    CriticalCVSS 9.8No exploitEPSS 1%

    aveva · suitelinkSep 23, 2021

  • CVE-2023-1256
    39Monitor

    The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an

    CriticalCVSS 9.8No exploitEPSS 1%

    aveva · aveva plant scadaMar 16, 2023

  • AVEVA Process Optimization SQL Injection

    CriticalCVSS 9.3No exploitEPSS 0%

    aveva · process optimizationJan 15, 2026

  • AVEVA Process Optimization Code Injection

    CriticalCVSS 9.3No exploitEPSS 0%

    aveva · process optimizationJan 15, 2026

  • AVEVA Process Optimization Uncontrolled Search Path Element

    CriticalCVSS 9.3No exploitEPSS 0%

    aveva · process optimizationJan 15, 2026

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802

    HighCVSS 7.8No exploitEPSS 17%

    aveva · aveva edgeMar 29, 2023

  • CVE-2019-6525
    35Monitor

    AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and i

    HighCVSS 8.8No exploitEPSS 1%

    aveva · wonderware system platformApr 11, 2019

  • CVE-2017-5156
    35Monitor

    A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior.

    HighCVSS 8.8No exploitEPSS 1%

    aveva · wonderware intouch access anywhereApr 20, 2017