Aveva develops industrial automation, control, and optimization software serving critical infrastructure and manufacturing environments, with a focused product portfolio including Edge, System Platform, and ClearSCADA that span edge computing, process control, and SCADA applications. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, while the exposure recurs through weakness classes including SQL injection, uncontrolled search path elements, and sensitive information exposure that reflect the integration and data-handling demands of industrial software stacks. The vendor's prominence in operational technology and process-critical deployments amplifies the impact of these flaws, as patching cycles in industrial environments often lag behind disclosure. Defenders should prioritize Aveva advisories for internet-reachable or process-adjacent instances and maintain close tracking of the vendor's update cadence; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aveva over time
Signals from CVEs in this vendor scope (68 CVEs).
68 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23854HIGH AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on th | Dec 23, 2022 | 7.5 | 69 | NO | YES |
CVE-2019-6543CRITICAL AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the pr | Feb 13, 2019 | 9.8 | 52 | NO | YES |
CVE-2019-6545HIGH AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. An unauthenticated remote use | Feb 13, 2019 | 7.5 | 37 | NO | YES |
CVE-2025-61937CRITICAL The vulnerability, if exploited, could allow an unauthenticated
miscreant to achieve remote code execution under OS system privileges of
“taoimr” service, potentially resulting i | Jan 16, 2026 | 10.0 | 35 | NO | NO |
CVE-2018-10620CRITICAL AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully crafted packet to exploit a stack-based buf | Jul 19, 2018 | 9.8 | 33 | NO | NO |
CVE-2022-28685HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to | Mar 29, 2023 | 7.8 | 32 | NO | NO |
CVE-2018-17914CRITICAL InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated | Nov 2, 2018 | 9.8 | 32 | NO | NO |
CVE-2021-33008CRITICAL AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requires a provable user identity. | Apr 4, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-42796CRITICAL An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticated arbitrary commands to be executed. | Dec 16, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-32959CRITICAL Heap-based buffer overflow in SuiteLink server while processing commands 0x05/0x06 | Sep 23, 2021 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (68 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aveva.
Media articles that mention a CVE ID that affects a product developed by Aveva — matched by CVE ID, not by vendor name.