Vulnerability Description
The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aveva | Intouch 2017 | - |
| Aveva | Intouch 2020 | - |
Related Weaknesses (CWE)
References
- https://us-cert.cisa.gov/ics/advisories/icsa-21-159-03PatchThird Party AdvisoryUS Government Resource
- https://www.aveva.com/en/support/cyber-security-updates/PatchVendor Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-159-03PatchThird Party AdvisoryUS Government Resource
- https://www.aveva.com/en/support/cyber-security-updates/PatchVendor Advisory
FAQ
What is CVE-2021-32942?
CVE-2021-32942 is a vulnerability with a CVSS score of 6.6 (MEDIUM). The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the ...
How severe is CVE-2021-32942?
CVE-2021-32942 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-32942?
Check the references section above for vendor advisories and patch information. Affected products include: Aveva Intouch 2017, Aveva Intouch 2020.