漏洞描述
AVEVA InTouch Access Anywhere Secure Gateway is vulnerable to local file inclusion.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
packetstormsecurity.comhttps://packetstormsecurity.com/files/cve/CVE-2022-23854↗www.aveva.comhttps://www.aveva.com↗crisec.dehttps://crisec.de/advisory-aveva-intouch-access-anywhere-secure-gateway-path-traversal↗cve.mitre.orghttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23854↗www.cisa.govhttps://www.cisa.gov/uscert/ics/advisories/icsa-22-342-02↗