HIGH · 7.3

CVE-2021-38410

AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker co...

Vulnerability Description

AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.

CVSS Score

7.3

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
AvevaBatch Management2020
AvevaEnterprise Data Management2020
AvevaManufacturing Execution System2020
AvevaMobile Operator2020
AvevaPlatform Common Services4.4.6
AvevaSystem Platform2020
AvevaWork Tasks2020

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-38410?

CVE-2021-38410 is a vulnerability with a CVSS score of 7.3 (HIGH). AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker co...

How severe is CVE-2021-38410?

CVE-2021-38410 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-38410?

Check the references section above for vendor advisories and patch information. Affected products include: Aveva Batch Management, Aveva Enterprise Data Management, Aveva Manufacturing Execution System, Aveva Mobile Operator, Aveva Platform Common Services.