CVE-2017-5156: Aveva Wonderware Intouch Access Anywhere

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client request may be forged from a different site. This will allow an external site to access internal RDP systems on behalf of the currently logged in user.

Affected products

  • Aveva Wonderware Intouch Access Anywhere: up to and including 11.5.2

Published 2017-04-20. Last modified 2026-06-17.