This content is restricted.
Brief
Summary:
The AVEVA Edge View CSAF provides an executive summary of a vulnerability with a CVSS v3 score of 7.3, resulting in arbitrary code execution and privilege escalation. The vulnerable AVEVA Edge products (formerly InduSoft Web Studio) are affected by an uncontrolled search path element, allowing a malicious entity to execute arbitrary code and escalate privileges. The vulnerability is not exploitable remotely. AVEVA recommends upgrading to AVEVA Edge 2023 or AVEVA Edge 2020 R2 SP2 P01 as soon as possible. CISA advises organizations to take defensive measures, perform proper impact analysis and risk assessment, and implement recommended cybersecurity strategies for proactive defense.
Highlights content goes here...
This content is restricted.
