7.2

CVE-2021-32985

AVEVA System Platform Origin Validation Error

AVEVA System Platform versions 2017 through 2020 R2 P01 does not properly verify that the source of data or communication is valid.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Aveva ≫ System Platform Version >= 2017 < 2020
Aveva ≫ System Platform Version 2020 Update -
Aveva ≫ System Platform Version 2020 Update r2
Aveva ≫ System Platform Version 2020 Update r2_p01
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.49% 0.397
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
DHS.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-346 Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2021-002.pdf
Vendor Advisory
https://www.cisa.gov/uscert/ics/advisories/icsa-21-180-05
Third Party Advisory
US Government Resource