PT-2022-6508 · Aveva · Aveva Intouch Access Anywhere
Crisec
+1
·
Published
2022-12-23
·
Updated
2024-01-19
·
CVE-2022-23854
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AVEVA InTouch Access Anywhere versions 2020 R2 and older
Description
The issue is related to errors in processing relative path to directory, which could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server. This can be exploited using a path traversal exploit. If an attacker gains access to confidential information, such as configuration files containing access data, it may lead to serious problems. The vulnerability can be easily exploited using a command-line tool like curl, and user interaction is not required. Over 1100 systems are accessible, allowing remote attackers to exploit the vulnerability directly from the internet.
Recommendations
For AVEVA InTouch Access Anywhere versions 2020 R2 and older, update to the latest version that includes the fix for this issue, as provided by the vendor. As a temporary workaround, consider restricting access to the secure gateway web server to minimize the risk of exploitation.
Exploit
Fix
Path traversal
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aveva Intouch Access Anywhere