7.2
CVE-2021-32985
- EPSS 0.49%
- Veröffentlicht 04.04.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:08:04
- Erkennungen
AVEVA System Platform Origin Validation Error
AVEVA System Platform versions 2017 through 2020 R2 P01 does not properly verify that the source of data or communication is valid.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Aveva ≫ System Platform Version >= 2017 < 2020
Aveva ≫ System Platform Version 2020 Update -
Aveva ≫ System Platform Version 2020 Update r2
Aveva ≫ System Platform Version 2020 Update r2_p01
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.49% | 0.397 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
| DHS.gov | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-346 Origin Validation Error
The product does not properly verify that the source of data or communication is valid.
https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2021-002.pdf
https://www.cisa.gov/uscert/ics/advisories/icsa-21-180-05