PT-2022-6508 · Aveva · Aveva Intouch Access Anywhere

Crisec

+1

·

Published

2022-12-23

·

Updated

2024-01-19

·

CVE-2022-23854

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions AVEVA InTouch Access Anywhere versions 2020 R2 and older
Description The issue is related to errors in processing relative path to directory, which could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server. This can be exploited using a path traversal exploit. If an attacker gains access to confidential information, such as configuration files containing access data, it may lead to serious problems. The vulnerability can be easily exploited using a command-line tool like curl, and user interaction is not required. Over 1100 systems are accessible, allowing remote attackers to exploit the vulnerability directly from the internet.
Recommendations For AVEVA InTouch Access Anywhere versions 2020 R2 and older, update to the latest version that includes the fix for this issue, as provided by the vendor. As a temporary workaround, consider restricting access to the secure gateway web server to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Relative Path Traversal

Weakness Enumeration

Related Identifiers

BDU:2023-01804
CVE-2022-23854

Affected Products

Aveva Intouch Access Anywhere