Description
The vulnerability, if exploited, could allow a miscreant with read access to Edge Project files or Edge Offline Cache files to reverse engineer Edge users' app-native or Active Directory passwords through computational brute-forcing of weak hashes.
Problem types
Product status
Any version
Credits
Joao Varelas reported this vulnerability to AVEVA.
References
www.aveva.com/...updates/SecurityBulletin_AVEVA-2025-006.pdf
www.cisa.gov/news-events/ics-advisories/icsa-25-317-03
github.com/...p/csaf_files/OT/white/2025/icsa-25-317-03.json