7.8

CVE-2021-38410

AVEVA PCS Portal Uncontrolled Search Path Element

AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Aveva ≫ Batch Management Version 2020
Aveva ≫ Mobile Operator Version 2020
Aveva ≫ Platform Common Services Version 4.4.6
Aveva ≫ Platform Common Services Version 4.5.0
Aveva ≫ Platform Common Services Version 4.5.1
Aveva ≫ Platform Common Services Version 4.5.2
Aveva ≫ System Platform Version 2020 Update -
Aveva ≫ System Platform Version 2020 Update r2
Aveva ≫ System Platform Version 2020 Update r2_p01
Aveva ≫ Work Tasks Version 2020 Update -
Aveva ≫ Work Tasks Version 2020 Update update_1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.129
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
DHS.gov 7.3 1.3 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

https://www.aveva.com/en/support-and-success/cyber-security-updates/
Vendor Advisory
https://www.cisa.gov/uscert/ics/advisories/icsa-21-252-01
Third Party Advisory
US Government Resource