First published: Thu Sep 23 2021(Updated: )
Null pointer dereference in SuiteLink server while processing commands 0x03/0x10
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Aveva Suitelink | <3.2.002 |
AVEVA recommends organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Users with affected versions of these products should apply the corresponding security update. Note a subset of the updates requires activation-based licensing. Please see AVEVA security bulletin AVEVA-2021-003 for more information.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32963 is a null pointer dereference vulnerability in the SuiteLink server while processing commands.
The severity of CVE-2021-32963 is high with a CVSS score of 7.5.
Aveva Suitelink versions up to and excluding 3.2.002 are affected by CVE-2021-32963.
To fix CVE-2021-32963, update Aveva Suitelink to version 3.2.002 or above.
You can find more information about CVE-2021-32963 in the Aveva Security Bulletin AVEVA-2021-003 (link: https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2021-003.pdf).