CVE-2017-5156: Aveva Wonderware Intouch Access Anywhere
High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.
A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client request may be forged from a different site. This will allow an external site to access internal RDP systems on behalf of the currently logged in user.
Affected products
- Aveva Wonderware Intouch Access Anywhere: up to and including 11.5.2
Published 2017-04-20. Last modified 2026-06-17.