AVEVA InTouch Access Anywhere Exposure of Resource to Wrong Sphere
CVE-2022-1467
7.4HIGH
What is CVE-2022-1467?
Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is possible to manipulate the Windows OS language bar to launch an OS command prompt, resulting in a context-escape from application into OS.
Affected Version(s)
AVEVA InTouch Access Anywhere all
AVEVA Plant SCADA Access Anywhere all
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Giovanni Delvecchio from Aceaspa reported this vulnerability to AVEVA.