AVEVA kayıtları
aveva üreticisine ait 71 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-427 Uncontrolled Search Path Element6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-121 Stack-based Buffer Overflow4
- CWE-476 NULL Pointer Dereference4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
71 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2022-23854Kavram kanıtı | AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated useraveva · intouch access anywhere · CWE-23 | Yüksek7,5 | — | %46,0 | 23 Ara 2022 |
44Planlayın | CVE-2019-6543Kavram kanıtı | AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20aveva · indusoft web studio · CWE-306 | Kritik9,8 | — | %17,3 | 12 Şub 2019 |
42Planlayın | CVE-2011-3143İstismar yok | Use-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 andaveva · clearscada · CWE-399 | Kritik10,0 | — | %7,5 | 16 Ağu 2011 |
41Planlayın | CVE-2018-10628İstismar yok | AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthenticated user to send a aveva · intouch 2014 · CWE-121 | Kritik9,8 | — | %5,4 | 24 Tem 2018 |
40Planlayın | CVE-2018-17914İstismar yok | InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.aveva · indusoft web studio · CWE-258 | Kritik9,8 | — | %4,6 | 2 Kas 2018 |
40Planlayın | CVE-2018-10620İstismar yok | AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully craaveva · indusoft web studio · CWE-121 | Kritik9,8 | — | %4,2 | 19 Tem 2018 |
40Planlayın | CVE-2018-17916İstismar yok | InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.aveva · indusoft web studio · CWE-121 | Kritik9,8 | — | %3,7 | 2 Kas 2018 |
40Planlayın | CVE-2020-13501İstismar yok | An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.aveva · edna enterprise data historian · CWE-89 | Kritik9,8 | — | %2,9 | 24 Eyl 2020 |
40Planlayın | CVE-2020-13500İstismar yok | SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.aveva · edna enterprise data historian · CWE-89 | Kritik9,8 | — | %2,9 | 24 Eyl 2020 |
40Planlayın | CVE-2020-13499İstismar yok | An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.aveva · edna enterprise data historian · CWE-89 | Kritik9,8 | — | %2,9 | 24 Eyl 2020 |
40Planlayın | CVE-2017-5158İstismar yok | An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior.aveva · wonderware intouch access anywhere · CWE-200 | Kritik9,8 | — | %2,4 | 20 Nis 2017 |
40Planlayın | CVE-2025-61937İstismar yok | AVEVA Process Optimization Code Injectionaveva · process optimization · CWE-94 | Kritik10,0 | — | %1,5 | 15 Oca 2026 |
39İzleyin | CVE-2020-13504İstismar yok | Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks.aveva · edna enterprise data historian · CWE-89 | Kritik9,8 | — | %1,2 | 24 Eyl 2020 |
39İzleyin | CVE-2020-13505İstismar yok | Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks.aveva · edna enterprise data historian · CWE-89 | Kritik9,8 | — | %1,2 | 24 Eyl 2020 |
39İzleyin | CVE-2021-33008İstismar yok | AVEVA System Platform Missing Authentication for Critical Functionaveva · system platform · CWE-306 | Kritik9,8 | — | %1,2 | 4 Nis 2022 |
39İzleyin | CVE-2021-42796İstismar yok | An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticateaveva · edge · CWE-78 | Kritik9,8 | — | %1,1 | 15 Ara 2023 |
39İzleyin | CVE-2022-1467İstismar yok | AVEVA InTouch Access Anywhere Exposure of Resource to Wrong Sphereaveva · intouch access anywhere · CWE-668 | Kritik9,9 | — | %1,0 | 23 May 2022 |
39İzleyin | CVE-2021-32959İstismar yok | AVEVA SuiteLink Server Buffer Overflowaveva · suitelink · CWE-122 | Kritik9,8 | — | %0,9 | 23 Eyl 2021 |
39İzleyin | CVE-2023-1256İstismar yok | The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow anaveva · aveva plant scada · CWE-285 | Kritik9,8 | — | %0,7 | 16 Mar 2023 |
37İzleyin | CVE-2025-61943İstismar yok | AVEVA Process Optimization SQL Injectionaveva · process optimization · CWE-89 | Kritik9,3 | — | %0,3 | 15 Oca 2026 |
37İzleyin | CVE-2025-64691İstismar yok | AVEVA Process Optimization Code Injectionaveva · process optimization · CWE-94 | Kritik9,3 | — | %0,3 | 15 Oca 2026 |
37İzleyin | CVE-2025-65118İstismar yok | AVEVA Process Optimization Uncontrolled Search Path Elementaveva · process optimization · CWE-427 | Kritik9,3 | — | %0,3 | 15 Oca 2026 |
36İzleyin | CVE-2022-28685İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802aveva · aveva edge · CWE-502 | Yüksek7,8 | — | %17,2 | 29 Mar 2023 |
35İzleyin | CVE-2019-6525İstismar yok | AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and iaveva · wonderware system platform · CWE-522 | Yüksek8,8 | — | %1,3 | 11 Nis 2019 |
35İzleyin | CVE-2017-5156İstismar yok | A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior.aveva · wonderware intouch access anywhere · CWE-352 | Yüksek8,8 | — | %1,0 | 20 Nis 2017 |
- CVE-2022-2385444Planlayın
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user
YüksekCVSS 7,5Kavram kanıtıEPSS %46aveva · intouch access anywhere23 Ara 2022
- CVE-2019-654344Planlayın
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20
KritikCVSS 9,8Kavram kanıtıEPSS %17aveva · indusoft web studio12 Şub 2019
- CVE-2011-314342Planlayın
Use-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and
KritikCVSS 10,0İstismar yokEPSS %8aveva · clearscada16 Ağu 2011
- CVE-2018-1062841Planlayın
AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthenticated user to send a
KritikCVSS 9,8İstismar yokEPSS %5aveva · intouch 201424 Tem 2018
- CVE-2018-1791440Planlayın
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.
KritikCVSS 9,8İstismar yokEPSS %5aveva · indusoft web studio2 Kas 2018
- CVE-2018-1062040Planlayın
AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully cra
KritikCVSS 9,8İstismar yokEPSS %4aveva · indusoft web studio19 Tem 2018
- CVE-2018-1791640Planlayın
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.
KritikCVSS 9,8İstismar yokEPSS %4aveva · indusoft web studio2 Kas 2018
- CVE-2020-1350140Planlayın
An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.
KritikCVSS 9,8İstismar yokEPSS %3aveva · edna enterprise data historian24 Eyl 2020
- CVE-2020-1350040Planlayın
SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.
KritikCVSS 9,8İstismar yokEPSS %3aveva · edna enterprise data historian24 Eyl 2020
- CVE-2020-1349940Planlayın
An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.
KritikCVSS 9,8İstismar yokEPSS %3aveva · edna enterprise data historian24 Eyl 2020
- CVE-2017-515840Planlayın
An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior.
KritikCVSS 9,8İstismar yokEPSS %2aveva · wonderware intouch access anywhere20 Nis 2017
- CVE-2025-6193740Planlayın
AVEVA Process Optimization Code Injection
KritikCVSS 10,0İstismar yokEPSS %2aveva · process optimization15 Oca 2026
- CVE-2020-1350439İzleyin
Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks.
KritikCVSS 9,8İstismar yokEPSS %1aveva · edna enterprise data historian24 Eyl 2020
- CVE-2020-1350539İzleyin
Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks.
KritikCVSS 9,8İstismar yokEPSS %1aveva · edna enterprise data historian24 Eyl 2020
- CVE-2021-3300839İzleyin
AVEVA System Platform Missing Authentication for Critical Function
KritikCVSS 9,8İstismar yokEPSS %1aveva · system platform4 Nis 2022
- CVE-2021-4279639İzleyin
An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticate
KritikCVSS 9,8İstismar yokEPSS %1aveva · edge15 Ara 2023
- CVE-2022-146739İzleyin
AVEVA InTouch Access Anywhere Exposure of Resource to Wrong Sphere
KritikCVSS 9,9İstismar yokEPSS %1aveva · intouch access anywhere23 May 2022
- CVE-2021-3295939İzleyin
AVEVA SuiteLink Server Buffer Overflow
KritikCVSS 9,8İstismar yokEPSS %1aveva · suitelink23 Eyl 2021
- CVE-2023-125639İzleyin
The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an
KritikCVSS 9,8İstismar yokEPSS %1aveva · aveva plant scada16 Mar 2023
- CVE-2025-6194337İzleyin
AVEVA Process Optimization SQL Injection
KritikCVSS 9,3İstismar yokEPSS %0aveva · process optimization15 Oca 2026
- CVE-2025-6469137İzleyin
AVEVA Process Optimization Code Injection
KritikCVSS 9,3İstismar yokEPSS %0aveva · process optimization15 Oca 2026
- CVE-2025-6511837İzleyin
AVEVA Process Optimization Uncontrolled Search Path Element
KritikCVSS 9,3İstismar yokEPSS %0aveva · process optimization15 Oca 2026
- CVE-2022-2868536İzleyin
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802
YüksekCVSS 7,8İstismar yokEPSS %17aveva · aveva edge29 Mar 2023
- CVE-2019-652535İzleyin
AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and i
YüksekCVSS 8,8İstismar yokEPSS %1aveva · wonderware system platform11 Nis 2019
- CVE-2017-515635İzleyin
A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior.
YüksekCVSS 8,8İstismar yokEPSS %1aveva · wonderware intouch access anywhere20 Nis 2017