CVE-2022-28688 is a remote code execution vulnerability affecting AVEVA Edge 2020 SP2 Patch 0 (4201.2111.1802.0000). The flaw, categorized as CWE-427, stems from the process loading a library from an unsecured location when handling APP files. Exploitation requires user interaction, where a target must visit a malicious page or open a malicious file, allowing an attacker to execute code in the context of the current process. Rated with a CVSS score of 7.8 (High), this vulnerability has no known public exploits, Metasploit modules, or Nuclei templates, and shows no community discussion or media coverage, indicating a low current exploitation risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2020.2.00.40CPE matchmatch criteria | cpe:2.3:a:aveva:aveva_edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.