An issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a client to provide a malicious connection string that could allow an adversary to port scan the LAN, depending on the hosts responses.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Edge | Aveva | * | 2020 (excluding) |
| Edge | Aveva | 2020 (including) | 2020 (including) |
| Edge | Aveva | 2020-r2 (including) | 2020-r2 (including) |