Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Aveva

First CVE: Aug 16, 2011Active for: 15 yearsTotal CVEs: 68
45.1
VTI Score
High

Aveva develops industrial automation, control, and optimization software serving critical infrastructure and manufacturing environments, with a focused product portfolio including Edge, System Platform, and ClearSCADA that span edge computing, process control, and SCADA applications. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, while the exposure recurs through weakness classes including SQL injection, uncontrolled search path elements, and sensitive information exposure that reflect the integration and data-handling demands of industrial software stacks. The vendor's prominence in operational technology and process-critical deployments amplifies the impact of these flaws, as patching cycles in industrial environments often lag behind disclosure. Defenders should prioritize Aveva advisories for internet-reachable or process-adjacent instances and maintain close tracking of the vendor's update cadence; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
68
Total CVEs
More Total CVEs than 99% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Aveva over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 16, 2011
14 years ago
Most Recent CVE
Jan 16, 2026
189 days ago

Products(35 total)

Top CVEs

Signals from CVEs in this vendor scope (68 CVEs).

68 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-23854HIGH
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on th
Dec 23, 20227.569NOYES
CVE-2019-6543CRITICAL
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the pr
Feb 13, 20199.852NOYES
CVE-2019-6545HIGH
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. An unauthenticated remote use
Feb 13, 20197.537NOYES
CVE-2025-61937CRITICAL
The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of “taoimr” service, potentially resulting i
Jan 16, 202610.035NONO
CVE-2018-10620CRITICAL
AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully crafted packet to exploit a stack-based buf
Jul 19, 20189.833NONO
CVE-2022-28685HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to
Mar 29, 20237.832NONO
CVE-2018-17914CRITICAL
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated
Nov 2, 20189.832NONO
CVE-2021-33008CRITICAL
AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requires a provable user identity.
Apr 4, 20229.831NONO
CVE-2021-42796CRITICAL
An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticated arbitrary commands to be executed.
Dec 16, 20239.830NONO
CVE-2021-32959CRITICAL
Heap-based buffer overflow in SuiteLink server while processing commands 0x05/0x06
Sep 23, 20219.830NONO
View all 68 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products68 CVEs
16%
53%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local18 (26.5%)
Network38 (55.9%)
Unknown11 (16.2%)
Physical0 (0.0%)
Adjacent Network1 (1.5%)
Attack Complexity
Low55 (80.9%)
High2 (2.9%)
Unknown11 (16.2%)
User Interaction
None45 (66.2%)
Unknown11 (16.2%)
Required12 (17.6%)
Privileges Required
Low11 (16.2%)
High4 (5.9%)
None42 (61.8%)
Unknown11 (16.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (68 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.5% of CVEs· 95th percentile
ExploitDB
3 CVEs
4.4% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Aveva.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Aveva — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Aveva's Products

View all 5 CNAs →

Top CWEs