Vulnerability Description
AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aveva | Batch Management | 2020 |
| Aveva | Enterprise Data Management | 2020 |
| Aveva | Manufacturing Execution System | 2020 |
| Aveva | Mobile Operator | 2020 |
| Aveva | Platform Common Services | 4.4.6 |
| Aveva | System Platform | 2020 |
| Aveva | Work Tasks | 2020 |
Related Weaknesses (CWE)
References
- https://www.aveva.com/en/support-and-success/cyber-security-updates/Vendor Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-252-01Third Party AdvisoryUS Government Resource
- https://www.aveva.com/en/support-and-success/cyber-security-updates/Vendor Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-252-01Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2021-38410?
CVE-2021-38410 is a vulnerability with a CVSS score of 7.3 (HIGH). AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker co...
How severe is CVE-2021-38410?
CVE-2021-38410 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-38410?
Check the references section above for vendor advisories and patch information. Affected products include: Aveva Batch Management, Aveva Enterprise Data Management, Aveva Manufacturing Execution System, Aveva Mobile Operator, Aveva Platform Common Services.