Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

In March 2023, AVEVA and CISA notified users of three vulnerabilities in AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere. The most serious listed component issue carried a maximum CVSS v3.1 score of 9.8 Critical; a separate path traversal issue could let an unauthenticated remote user read arbitrary files from the host. AVEVA’s remediation guidance named newer product versions for installations in mainstream support and warned that older versions had no hot fixes.

Which AVEVA products were affected?

AVEVA’s March 14, 2023 security bulletin, AVEVA-2023-001, lists these affected product ranges:

Product Affected versions in the bulletin Notes
AVEVA InTouch Access Anywhere 2023 and all prior versions Available as a standalone product or as an optional System Platform sub-feature.
AVEVA Plant SCADA Access Anywhere 2020 R2 and all prior versions Formerly known as Citect Anywhere.

These are the ranges stated in the 2023 bulletin, not confirmation that a given installation remains affected today. Check AVEVA’s security updates index and confirm current support and package availability with the vendor before using historical upgrade directions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What were the three vulnerabilities?

The bulletin covers outdated OpenSSL, a path traversal flaw, and outdated jQuery. Its scores are maximum listed CVSS v3.1 component scores; they are not a single rating that applies equally to all three issues.

Issue Products noted Maximum listed CVSS v3.1 score What it means
Outdated OpenSSL, including CVE-2021-3711 InTouch Access Anywhere and Plant SCADA Access Anywhere 9.8 Critical The bulletin identifies OpenSSL versions before 1.1.1q as affected.
Path traversal, CVE-2022-23854 Both Access Anywhere products 7.5 High An unauthenticated remote user may be able to read arbitrary files on the host, creating an information-disclosure risk. The bulletin says functional exploit code is publicly available.
Outdated jQuery, including CVE-2020-11022 Both Access Anywhere products 6.1 Medium The bulletin identifies jQuery versions before 3.5.0.

Why the path traversal drew particular concern

SecurityWeek reported that Jens Regel, a consultant at CRISEC, discovered the path traversal and disclosed it after the vendor had released a hotfix. Regel described the flaw as allowing access to files on the host when their paths are known. The practical concern is that the file-read issue was remotely exploitable without authentication; it is distinct from the OpenSSL and jQuery component findings. SecurityWeek’s March 21, 2023 report quoted Regel saying no user interaction was necessary and that it could be exploited using a command-line tool.

How did AVEVA say supported installations could be remediated?

AVEVA’s bulletin says affected versions in mainstream support can be remediated by uninstalling the old version and installing the applicable newer release:

Rank #2
HMI PLC All in One, 7in TFT LCD Display, Touch Screen PLC Controller Relay Output 12in 8out High Speed Counting, Fast Running Speed, Simple Installation with
  • [Simple Installation] With a hole size of 190x135 mm and complete with screws and fixing accessories, the HMI PLC all in one machine can be directly installed without hassle. It has a clock feature.
  • [Vivid Tft Lcd Display] This HMI PLC controller is suitable for industrial automation. 7-Inch screen with high resolution, vivid colors, and bright backlight, offering easy status observation. industrial touch screen for durability. The screen resolution is 800x480px.
  • [Efficient Plc Programming] Supports fast download speeds and can be used with gx developer or gx works2 for programming, debugging, and monitoring.
  • [Intuitive Hmi Programming] Compatible with hmi studio 5.1 software, allowing seamless programming through usb connectivity. The package list includes 1 x HMI PLC, 4 x Installation Screws, 4 x Fixing Brackets.
  • [ Hmi Plc] Features a powerful arm9 processor, 128m nand flash memory, and compatibility with fx3u series, ensuring and fast .
  • InTouch Access Anywhere: install version 2023b or later.
  • Plant SCADA Access Anywhere: install version 2023 or later.

AVEVA stated that hot fixes for older versions were not available. Because this is guidance from March 2023, verify the current supported release, upgrade path, and installation instructions with AVEVA before acting on a present-day system.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What operational precautions did AVEVA recommend?

AVEVA advised organizations to assess risk in the context of their operational environment, architecture, and product implementation, and to apply security updates as soon as possible. It also recommended firewall rules to reduce network exposure of the Access Anywhere Secure Gateway service. That is vendor guidance, not a one-size-fits-all network design; administrators should account for site-specific remote-access requirements and safety constraints.

Rank #3
HMI HMI TFT LCD Display Module Touchscreen Monitor 7in PLC Control Screen 12 in 8 Out DC 24V 5A Relay Output Module for FX3U‑20/40/48MRT
  • Premium Design: The HMI adopts 32 bit 240MHz ARM9 and 128M NAND FLASH memory with a download speed of 38.4KB, mainly used for various PLCs or intelligent controllers with communication ports, compatible with FX3U‑20/40/48MRT.
  • Clear in Display: 7in TFT LCD screen with 800 x 480px resolution, 400cd/m² brightness with backlight display, easy to observe.
  • The is equipped with an ARM9 processor, resulting in high touch accuracy. The front panel complies with lP65 flat panel installation, and the rear shell of the body complies with IP20.
  • Wide Application: This is a small human machine interface mainly used for various PLCs or intelligent controllers with communication ports. has low power consumption, fast speed, and
  • Easy Installation: The opening size is 190mm x 136mm, equipped with screws and fixing accessories, can be installed directly.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Was there a separate Plant SCADA and Telemetry Server advisory?

Yes. SecurityWeek separately reported a critical vulnerability discovered by the UK’s National Cyber Security Centre in AVEVA Plant SCADA and Telemetry Server. The report said an unauthenticated remote attacker could read data, cause denial of service, and tamper with alarm states. CISA’s advisory index lists ICSA-23-073-04, “AVEVA Plant SCADA and AVEVA Telemetry Server,” dated March 14, 2023. CISA’s index is the source for that listing.

This is a separate issue from AVEVA-2023-001’s Access Anywhere vulnerabilities. The available information here does not establish CVE identifiers, affected version ranges, or remediation versions for the Plant SCADA and Telemetry Server flaw, so none should be inferred from the Access Anywhere bulletin. CISA’s March 16, 2023 notice also confirms an update to ICSA-22-342-02 for InTouch Access Anywhere and Plant SCADA Access Anywhere: CISA’s release announcement.

Best Value
Arrvel N15L6 All-in-One Industrial Panel PC, 15.6" FHD Touchscreen Computer, Windows 11 Pro, Intel N5095, 8+128GB, Fanless HMI PC, IP65 Front Panel, Dual RS232 for Machine Control & Factory Automation
  • [ FHD Touchscreen Control ] - The Arrvel N15L6 industrial panel PC combines a 1920 x 1080 display with 10-point touch for viewing production data and navigating operator controls. Preinstalled Windows 11 Pro provides a platform for compatible HMI and machine-control software, MES/ERP access, PLM data viewing, and electronic work instructions (ESOP).
  • [ Fanless Computing Performance ] - Equipped with a quad-core Intel N5095 processor up to 2.9 GHz, 8GB DDR4 RAM, and a 128GB M.2 SSD for production monitoring, data collection, and dashboard applications. The fanless design uses rear cooling fins to dissipate heat without fan noise, supporting quiet operation on the factory floor.
  • [ Versatile Industrial Connectivity ] - Two RS232 DB9 ports connect serial and legacy industrial equipment. Gigabit Ethernet, built-in Wi-Fi, and Bluetooth provide wired and wireless connectivity. Peripheral connections include 2 x USB 3.0, 2 x USB 2.0, HDMI and VGA display outputs, plus line-out and microphone ports.
  • [ Flexible VESA Mounting ] - This all-in-one touchscreen computer integrates the PC, display, and touch controls in a compact 14.64 x 8.83 x 1.96-inch housing. VESA mounting support allows installation on compatible wall, arm, or workstation mounts for machine-side HMI stations, production dashboards, and warehouse workstations.
  • [ Industrial Build and Protection ] - The N15L6 features an aerospace-grade 6063-T5 aluminum enclosure that combines industrial durability with up to 50% better heat dissipation, helping deliver up to twice the CPU performance. Built for demanding industrial work areas, it is rated for operation from -10°C to 50°C (14°F to 122°F) and at 5%–95% non-condensing humidity, with an IP65-rated front panel that helps protect the operator-facing surface against dust and water exposure.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.