← Vulnerability feed

Vulnerability record · CVE-2021-42797 · published 16 December 2023

CVE-2021-42797: Aveva edge path traversal vulnerability

Aveva · Edge

Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources.

7.5 CVSS 3.1 High EPSS 1.0% · top 38.7% CWE-22 · Path traversal
7.5CVSS 3.1 base score
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-42797 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-42796Aveva edge os command injection vulnerabilityAn issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticated arbitra…EPSS 1.1%9.8CVE-2018-17914Aveva indusoft web studio vulnerabilityInduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability…EPSS 4.6%9.8CVE-2018-17916Aveva indusoft web studio stack-based buffer overflow vulnerabilityInduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker …EPSS 3.7%7.8CVE-2023-33873Aveva batch management execution with unnecessary privileges vulnerabilityThis privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privi…EPSS 0.24%7.1CVE-2023-34982Aveva batch management vulnerabilityThis external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System pri…EPSS 0.22%5.3CVE-2021-42794Aveva edge vulnerabilityAn issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a client to provide a malicious…EPSS 1.2%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed

Source: NIST National Vulnerability Database (record CVE-2021-42797), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.