AVEVA InTouch Access Anywhere Exposure of Resource to Wrong Sphere
CVE-2022-1467

7.4HIGH

What is CVE-2022-1467?

Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is possible to manipulate the Windows OS language bar to launch an OS command prompt, resulting in a context-escape from application into OS.

Affected Version(s)

AVEVA InTouch Access Anywhere all

AVEVA Plant SCADA Access Anywhere all

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Giovanni Delvecchio from Aceaspa reported this vulnerability to AVEVA.
.