CVE-2021-32981: AVEVA System Platform Path Traversal
AVEVA System Platform versions 2017 through 2020 R2 P01 uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-32981?
CVE-2021-32981 is a vulnerability in AVEVA System Platform versions 2017 through 2020 R2 P01 that allows an attacker to construct a pathname to access files or directories outside of the intended restricted directory.
How severe is CVE-2021-32981?
CVE-2021-32981 has a severity rating of 7.2 out of 10, indicating a high severity.
What is the affected software for CVE-2021-32981?
AVEVA System Platform versions 2017 through 2020 R2 P01 are affected by CVE-2021-32981.
How can I fix CVE-2021-32981?
To fix CVE-2021-32981, it is recommended to apply the security patch provided by AVEVA. Please refer to the AVEVA Security Bulletin for more information.
Where can I find more information about CVE-2021-32981?
You can find more information about CVE-2021-32981 in the AVEVA Security Bulletin and the CISA advisory.