Edge
Aveva · 7 CVEs
AVEVA Edge Use of a Broken or Risky Cryptographic Algorithm
Nov 14, 2025
Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenti…
Dec 16, 2023
An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that…
Dec 16, 2023
An issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a…
Dec 16, 2023
AVEVA Operations Control Logger External Control of File Name or Path
Nov 15, 2023
AVEVA Operations Control Logger Execution with Unnecessary Privileges
Nov 15, 2023
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 20.0 Build…
Mar 29, 2023
This vulnerability allows remote attackers to disclose sensitive information on affected installations of AVEVA Edge 20…
Mar 29, 2023
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 P…
Mar 29, 2023
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 P…
Mar 29, 2023
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 P…
Mar 29, 2023
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 P…
Mar 29, 2023
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior t…
Nov 2, 2018
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior t…
Nov 2, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-9317 | AVEVA Edge Use of a Broken or Risky Cryptographic Algorithm | HIGH | 0.10% | Nov 14, 2025 |
| CVE-2021-42797 | Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access t… | HIGH | 1.00% | Dec 16, 2023 |
| CVE-2021-42796 | An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticated arbitrary command… | CRITICAL | 1.13% | Dec 16, 2023 |
| CVE-2021-42794 | An issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a client to provide a malicious connectio… | MEDIUM | 1.20% | Dec 16, 2023 |
| CVE-2023-34982 | AVEVA Operations Control Logger External Control of File Name or Path | HIGH | 0.22% | Nov 15, 2023 |
| CVE-2023-33873 | AVEVA Operations Control Logger Execution with Unnecessary Privileges | HIGH | 0.24% | Nov 15, 2023 |
| CVE-2022-36970 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 20.0 Build: 4201.2111.1802.0000 Service Pack 2. Us… | HIGH | 0.65% | Mar 29, 2023 |
| CVE-2022-36969 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). Use… | HIGH | 13.79% | Mar 29, 2023 |
| CVE-2022-28688 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User intera… | HIGH | 0.65% | Mar 29, 2023 |
| CVE-2022-28687 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User intera… | HIGH | 0.98% | Mar 29, 2023 |
| CVE-2022-28686 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User intera… | HIGH | 0.65% | Mar 29, 2023 |
| CVE-2022-28685 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User intera… | HIGH | 17.16% | Mar 29, 2023 |
| CVE-2018-17916 | InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker could send… | CRITICAL | 3.73% | Nov 2, 2018 |
| CVE-2018-17914 | InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could all… | CRITICAL | 4.57% | Nov 2, 2018 |
Showing 1 to 7 of 7 CVEs