CVE-2022-23854 Scanner

This scanner tests the secure gateway web server for directory traversal via crafted HTTP requests, allowing unauthenticated file reads outside the web root.

Short Info


Level

High

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

1 month 11 days

Scan only one

URL

Toolbox

AVEVA InTouch Access Anywhere is a remote access solution for industrial control systems, enabling operators to monitor and manage plant-floor equipment from any location. It is commonly deployed in manufacturing, energy, and utilities to provide secure web-based access to SCADA and HMI applications without requiring VPNs or client software.

CVE-2022-23854 is a path traversal vulnerability that arises due to insufficient input validation in the secure gateway component. An attacker can manipulate file path parameters in HTTP requests to escape the intended web directory and read arbitrary files on the server, including configuration files and credentials.

The vulnerability is triggered through the secure gateway's file serving functionality, specifically by injecting directory traversal sequences (e.g., ../) into the request path. This allows an unauthenticated remote attacker to access files outside the web root, such as /etc/passwd or application configuration files.

If exploited, an attacker could gain access to sensitive system files, including authentication tokens, database credentials, and proprietary industrial process data. This could lead to further network compromise, data exfiltration, or disruption of critical infrastructure operations.

Get started to protecting your digital assets