HomeAvevaCVE-2022-1467

CVE-2022-1467

HIGH
7.4CVSS
Published: 2022-05-23
Updated: 2024-11-21
AI Analysis

Description

Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is possible to manipulate the Windows OS language bar to launch an OS command prompt, resulting in a context-escape from application into OS.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Attack Vector
network
Complexity
low
Privileges
low
User Action
none
Scope
changed
Confidentiality
low
Integrity
low
Availability
low
Weaknesses
CWE-668

Metadata

Primary Vendor
AVEVA
Published
5/23/2022
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

aveva : intouch_access_anywhereaveva : plant_scada_access_anywhere

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2022-1467 | HIGH Severity | CVEDatabase.com | CVEDatabase.com