← Back to browse · API

CVE-2022-23854

Severity
HIGH
CVSS
7.5
EPSS
0.45957
Risk score
46.08
CISA KEV
No
PoC
No
Published
2022-12-23
Modified
2025-02-13
First seen
2026-08-07
Aliases
EUVD-2022-28780, GHSA-CCVR-7M85-7G88
Products
AVEVA:InTouch Access Anywhere 0 ≤2020 R2
Sources
euvd EUVD-2022-28780

Description

AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server.

References