Remote Information Disclosure Vulnerability in AVEVA Edge by AVEVA
CVE-2022-36969
What is CVE-2022-36969?
The vulnerability located in the LoadImportedLibraries method of AVEVA Edge 2020 SP2 Patch 0 permits attackers to gain unauthorized access to sensitive information. This occurs when a user interacts with a malicious web page or file containing crafted XML, leading the XML parser to improperly process external entity references. As a result, an attacker can extract confidential data from the system, leveraging the current user's permissions. To mitigate this risk, users must be cautious about external documents and malicious URLs.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Edge 2020 SP2 Patch 0(4201.2111.1802.0000)
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
