7.8

CVE-2021-38410

AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AvevaBatch Management Version2020
AvevaMobile Operator Version2020
AvevaPlatform Common Services Version4.4.6
AvevaPlatform Common Services Version4.5.0
AvevaPlatform Common Services Version4.5.1
AvevaPlatform Common Services Version4.5.2
AvevaSystem Platform Version2020 Update-
AvevaSystem Platform Version2020 Updater2
AvevaSystem Platform Version2020 Updater2_p01
AvevaWork Tasks Version2020 Update-
AvevaWork Tasks Version2020 Updateupdate_1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.11% 0.298
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ics-cert@hq.dhs.gov 7.3 1.3 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.