İçeriğe atla
Noroxi

AVEVA kayıtları

aveva üreticisine ait 71 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
4
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

71 kayıt
  • CVE-2022-23854
    44Planlayın

    AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user

    YüksekCVSS 7,5Kavram kanıtıEPSS %46

    aveva · intouch access anywhere23 Ara 2022

  • CVE-2019-6543
    44Planlayın

    AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20

    KritikCVSS 9,8Kavram kanıtıEPSS %17

    aveva · indusoft web studio12 Şub 2019

  • CVE-2011-3143
    42Planlayın

    Use-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and

    KritikCVSS 10,0İstismar yokEPSS %8

    aveva · clearscada16 Ağu 2011

  • CVE-2018-10628
    41Planlayın

    AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthenticated user to send a

    KritikCVSS 9,8İstismar yokEPSS %5

    aveva · intouch 201424 Tem 2018

  • CVE-2018-17914
    40Planlayın

    InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.

    KritikCVSS 9,8İstismar yokEPSS %5

    aveva · indusoft web studio2 Kas 2018

  • CVE-2018-10620
    40Planlayın

    AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully cra

    KritikCVSS 9,8İstismar yokEPSS %4

    aveva · indusoft web studio19 Tem 2018

  • CVE-2018-17916
    40Planlayın

    InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.

    KritikCVSS 9,8İstismar yokEPSS %4

    aveva · indusoft web studio2 Kas 2018

  • CVE-2020-13501
    40Planlayın

    An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.

    KritikCVSS 9,8İstismar yokEPSS %3

    aveva · edna enterprise data historian24 Eyl 2020

  • CVE-2020-13500
    40Planlayın

    SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.

    KritikCVSS 9,8İstismar yokEPSS %3

    aveva · edna enterprise data historian24 Eyl 2020

  • CVE-2020-13499
    40Planlayın

    An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.

    KritikCVSS 9,8İstismar yokEPSS %3

    aveva · edna enterprise data historian24 Eyl 2020

  • CVE-2017-5158
    40Planlayın

    An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior.

    KritikCVSS 9,8İstismar yokEPSS %2

    aveva · wonderware intouch access anywhere20 Nis 2017

  • CVE-2025-61937
    40Planlayın

    AVEVA Process Optimization Code Injection

    KritikCVSS 10,0İstismar yokEPSS %2

    aveva · process optimization15 Oca 2026

  • CVE-2020-13504
    39İzleyin

    Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks.

    KritikCVSS 9,8İstismar yokEPSS %1

    aveva · edna enterprise data historian24 Eyl 2020

  • CVE-2020-13505
    39İzleyin

    Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks.

    KritikCVSS 9,8İstismar yokEPSS %1

    aveva · edna enterprise data historian24 Eyl 2020

  • CVE-2021-33008
    39İzleyin

    AVEVA System Platform Missing Authentication for Critical Function

    KritikCVSS 9,8İstismar yokEPSS %1

    aveva · system platform4 Nis 2022

  • CVE-2021-42796
    39İzleyin

    An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticate

    KritikCVSS 9,8İstismar yokEPSS %1

    aveva · edge15 Ara 2023

  • CVE-2022-1467
    39İzleyin

    AVEVA InTouch Access Anywhere Exposure of Resource to Wrong Sphere

    KritikCVSS 9,9İstismar yokEPSS %1

    aveva · intouch access anywhere23 May 2022

  • CVE-2021-32959
    39İzleyin

    AVEVA SuiteLink Server Buffer Overflow

    KritikCVSS 9,8İstismar yokEPSS %1

    aveva · suitelink23 Eyl 2021

  • CVE-2023-1256
    39İzleyin

    The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an

    KritikCVSS 9,8İstismar yokEPSS %1

    aveva · aveva plant scada16 Mar 2023

  • CVE-2025-61943
    37İzleyin

    AVEVA Process Optimization SQL Injection

    KritikCVSS 9,3İstismar yokEPSS %0

    aveva · process optimization15 Oca 2026

  • CVE-2025-64691
    37İzleyin

    AVEVA Process Optimization Code Injection

    KritikCVSS 9,3İstismar yokEPSS %0

    aveva · process optimization15 Oca 2026

  • CVE-2025-65118
    37İzleyin

    AVEVA Process Optimization Uncontrolled Search Path Element

    KritikCVSS 9,3İstismar yokEPSS %0

    aveva · process optimization15 Oca 2026

  • CVE-2022-28685
    36İzleyin

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802

    YüksekCVSS 7,8İstismar yokEPSS %17

    aveva · aveva edge29 Mar 2023

  • CVE-2019-6525
    35İzleyin

    AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and i

    YüksekCVSS 8,8İstismar yokEPSS %1

    aveva · wonderware system platform11 Nis 2019

  • CVE-2017-5156
    35İzleyin

    A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior.

    YüksekCVSS 8,8İstismar yokEPSS %1

    aveva · wonderware intouch access anywhere20 Nis 2017