An issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a client to provide a malicious connection string that could allow an adversary to port scan the LAN, depending on the hosts' responses.
This Cyber News was published on www.tenable.com. Publication date: Sat, 16 Dec 2023 17:41:03 +0000