Back to Database
Status published
Unknown
CVE-2021-42796
An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly...
Vulnerability Description
An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticated arbitrary commands to be executed.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-42796
Credits & Attribution
No credits recorded in the NVD database.
References
More from aveva
View All →CVE-2021-42797
Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio)...
High
7.5
CVE-2021-42794
An issue was discovered in AVEVA Edge (formerly InduSoft Web...
Medium
5.3
CVE-2015-0999
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4...
Low
2.1
CVE-2015-0998
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4...
Low
3.3
CVE-2015-0997
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4...
Medium
5
Affected Vendor
aveva
View all reports →Affected Software
edge
Vulnerable Versions:
0, 2020
Timeline
Official Publish:
December 16th, 2023
Last Modified:
October 7th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.