CVE-2021-38410: AVEVA PCS Portal Uncontrolled Search Path Element
AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-38410?
CVE-2021-38410 is a vulnerability in AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 that allows DLL hijacking through an uncontrolled search path element.
What is the severity of CVE-2021-38410?
The severity of CVE-2021-38410 is high with a CVSS score of 7.8.
Which software versions are affected by CVE-2021-38410?
AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are affected by CVE-2021-38410.
How can an attacker exploit CVE-2021-38410?
CVE-2021-38410 can be exploited by an attacker to gain control of one or more locations in the search path through DLL hijacking.
Where can I find more information about CVE-2021-38410?
You can find more information about CVE-2021-38410 on the AVEVA and CISA websites.