Записи AVEVA
71 опубликованных записей вендора aveva.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-427 Uncontrolled Search Path Element6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-121 Stack-based Buffer Overflow4
- CWE-476 NULL Pointer Dereference4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
71 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2022-23854Proof of concept | AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated useraveva · intouch access anywhere · CWE-23 | Высокая7,5 | — | 46,9 % | 23 дек. 2022 г. |
44В плане | CVE-2019-6543Proof of concept | AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20aveva · indusoft web studio · CWE-306 | Критическая9,8 | — | 17,3 % | 12 февр. 2019 г. |
42В плане | CVE-2011-3143Эксплойта нет | Use-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 andaveva · clearscada · CWE-399 | Критическая10,0 | — | 7,5 % | 16 авг. 2011 г. |
41В плане | CVE-2018-10628Эксплойта нет | AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthenticated user to send a aveva · intouch 2014 · CWE-121 | Критическая9,8 | — | 5,4 % | 24 июл. 2018 г. |
40В плане | CVE-2018-17914Эксплойта нет | InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.aveva · indusoft web studio · CWE-258 | Критическая9,8 | — | 4,6 % | 2 нояб. 2018 г. |
40В плане | CVE-2018-10620Эксплойта нет | AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully craaveva · indusoft web studio · CWE-121 | Критическая9,8 | — | 4,2 % | 19 июл. 2018 г. |
40В плане | CVE-2018-17916Эксплойта нет | InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.aveva · indusoft web studio · CWE-121 | Критическая9,8 | — | 3,7 % | 2 нояб. 2018 г. |
40В плане | CVE-2020-13501Эксплойта нет | An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.aveva · edna enterprise data historian · CWE-89 | Критическая9,8 | — | 2,9 % | 24 сент. 2020 г. |
40В плане | CVE-2020-13500Эксплойта нет | SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.aveva · edna enterprise data historian · CWE-89 | Критическая9,8 | — | 2,9 % | 24 сент. 2020 г. |
40В плане | CVE-2020-13499Эксплойта нет | An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.aveva · edna enterprise data historian · CWE-89 | Критическая9,8 | — | 2,9 % | 24 сент. 2020 г. |
40В плане | CVE-2017-5158Эксплойта нет | An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior.aveva · wonderware intouch access anywhere · CWE-200 | Критическая9,8 | — | 2,4 % | 20 апр. 2017 г. |
40В плане | CVE-2025-61937Эксплойта нет | AVEVA Process Optimization Code Injectionaveva · process optimization · CWE-94 | Критическая10,0 | — | 1,5 % | 15 янв. 2026 г. |
39Наблюдать | CVE-2020-13504Эксплойта нет | Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks.aveva · edna enterprise data historian · CWE-89 | Критическая9,8 | — | 1,2 % | 24 сент. 2020 г. |
39Наблюдать | CVE-2020-13505Эксплойта нет | Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks.aveva · edna enterprise data historian · CWE-89 | Критическая9,8 | — | 1,2 % | 24 сент. 2020 г. |
39Наблюдать | CVE-2021-33008Эксплойта нет | AVEVA System Platform Missing Authentication for Critical Functionaveva · system platform · CWE-306 | Критическая9,8 | — | 1,2 % | 4 апр. 2022 г. |
39Наблюдать | CVE-2021-42796Эксплойта нет | An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticateaveva · edge · CWE-78 | Критическая9,8 | — | 1,1 % | 15 дек. 2023 г. |
39Наблюдать | CVE-2022-1467Эксплойта нет | AVEVA InTouch Access Anywhere Exposure of Resource to Wrong Sphereaveva · intouch access anywhere · CWE-668 | Критическая9,9 | — | 1,0 % | 23 мая 2022 г. |
39Наблюдать | CVE-2021-32959Эксплойта нет | AVEVA SuiteLink Server Buffer Overflowaveva · suitelink · CWE-122 | Критическая9,8 | — | 0,9 % | 23 сент. 2021 г. |
39Наблюдать | CVE-2023-1256Эксплойта нет | The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow anaveva · aveva plant scada · CWE-285 | Критическая9,8 | — | 0,7 % | 16 мар. 2023 г. |
37Наблюдать | CVE-2025-61943Эксплойта нет | AVEVA Process Optimization SQL Injectionaveva · process optimization · CWE-89 | Критическая9,3 | — | 0,3 % | 15 янв. 2026 г. |
37Наблюдать | CVE-2025-64691Эксплойта нет | AVEVA Process Optimization Code Injectionaveva · process optimization · CWE-94 | Критическая9,3 | — | 0,3 % | 15 янв. 2026 г. |
37Наблюдать | CVE-2025-65118Эксплойта нет | AVEVA Process Optimization Uncontrolled Search Path Elementaveva · process optimization · CWE-427 | Критическая9,3 | — | 0,3 % | 15 янв. 2026 г. |
36Наблюдать | CVE-2022-28685Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802aveva · aveva edge · CWE-502 | Высокая7,8 | — | 17,2 % | 29 мар. 2023 г. |
35Наблюдать | CVE-2019-6525Эксплойта нет | AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and iaveva · wonderware system platform · CWE-522 | Высокая8,8 | — | 1,3 % | 11 апр. 2019 г. |
35Наблюдать | CVE-2017-5156Эксплойта нет | A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior.aveva · wonderware intouch access anywhere · CWE-352 | Высокая8,8 | — | 1,0 % | 20 апр. 2017 г. |
- CVE-2022-2385444В плане
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user
ВысокаяCVSS 7,5Proof of conceptEPSS 47 %aveva · intouch access anywhere23 дек. 2022 г.
- CVE-2019-654344В плане
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20
КритическаяCVSS 9,8Proof of conceptEPSS 17 %aveva · indusoft web studio12 февр. 2019 г.
- CVE-2011-314342В плане
Use-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %aveva · clearscada16 авг. 2011 г.
- CVE-2018-1062841В плане
AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthenticated user to send a
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %aveva · intouch 201424 июл. 2018 г.
- CVE-2018-1791440В плане
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %aveva · indusoft web studio2 нояб. 2018 г.
- CVE-2018-1062040В плане
AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully cra
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %aveva · indusoft web studio19 июл. 2018 г.
- CVE-2018-1791640В плане
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %aveva · indusoft web studio2 нояб. 2018 г.
- CVE-2020-1350140В плане
An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %aveva · edna enterprise data historian24 сент. 2020 г.
- CVE-2020-1350040В плане
SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %aveva · edna enterprise data historian24 сент. 2020 г.
- CVE-2020-1349940В плане
An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %aveva · edna enterprise data historian24 сент. 2020 г.
- CVE-2017-515840В плане
An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %aveva · wonderware intouch access anywhere20 апр. 2017 г.
- CVE-2025-6193740В плане
AVEVA Process Optimization Code Injection
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %aveva · process optimization15 янв. 2026 г.
- CVE-2020-1350439Наблюдать
Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %aveva · edna enterprise data historian24 сент. 2020 г.
- CVE-2020-1350539Наблюдать
Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %aveva · edna enterprise data historian24 сент. 2020 г.
- CVE-2021-3300839Наблюдать
AVEVA System Platform Missing Authentication for Critical Function
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %aveva · system platform4 апр. 2022 г.
- CVE-2021-4279639Наблюдать
An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticate
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %aveva · edge15 дек. 2023 г.
- CVE-2022-146739Наблюдать
AVEVA InTouch Access Anywhere Exposure of Resource to Wrong Sphere
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %aveva · intouch access anywhere23 мая 2022 г.
- CVE-2021-3295939Наблюдать
AVEVA SuiteLink Server Buffer Overflow
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %aveva · suitelink23 сент. 2021 г.
- CVE-2023-125639Наблюдать
The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %aveva · aveva plant scada16 мар. 2023 г.
- CVE-2025-6194337Наблюдать
AVEVA Process Optimization SQL Injection
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %aveva · process optimization15 янв. 2026 г.
- CVE-2025-6469137Наблюдать
AVEVA Process Optimization Code Injection
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %aveva · process optimization15 янв. 2026 г.
- CVE-2025-6511837Наблюдать
AVEVA Process Optimization Uncontrolled Search Path Element
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %aveva · process optimization15 янв. 2026 г.
- CVE-2022-2868536Наблюдать
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802
ВысокаяCVSS 7,8Эксплойта нетEPSS 17 %aveva · aveva edge29 мар. 2023 г.
- CVE-2019-652535Наблюдать
AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and i
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %aveva · wonderware system platform11 апр. 2019 г.
- CVE-2017-515635Наблюдать
A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %aveva · wonderware intouch access anywhere20 апр. 2017 г.