First published: Wed Jul 27 2022(Updated: )
AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Aveva Batch Management | =2020 | |
Aveva Enterprise Data Management | =2020 | |
Aveva Manufacturing Execution System | =2020 | |
Aveva Mobile Operator | =2020 | |
Aveva Platform Common Services | =4.4.6 | |
Aveva Platform Common Services | =4.5.0 | |
Aveva Platform Common Services | =4.5.1 | |
Aveva Platform Common Services | =4.5.2 | |
AVEVA System Platform | =2020 | |
AVEVA System Platform | =2020-r2 | |
AVEVA System Platform | =2020-r2_p01 | |
Aveva Work Tasks | =2020 | |
Aveva Work Tasks | =2020-update_1 | |
AVEVA PCS Versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 |
AVEVA recommends organizations evaluate the impact of this vulnerability based on their operational environment, architecture, and product implementation. Users of affected versions of the products should apply the corresponding security update as soon as possible. Security update PCS 4.5.3 is available for the following versions: AVEVA Mobile Operator 2020 AVEVA Enterprise Data Management 2021 AVEVA System Platform 2020 R2 P01 AVEVA System Platform 2020 R2 AVEVA Work Tasks 2020 Update 1 Security update PCS 4.4.7 is available for the following versions: AVEVA System Platform 2020 AVEVA Work Tasks 2020 AVEVA Manufacturing Execution System 2020 AVEVA Batch Management 2020 For more information on this issue, including security updates, please see Security Bulletin AVEVA-2021-008.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38410 is a vulnerability in AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 that allows DLL hijacking through an uncontrolled search path element.
The severity of CVE-2021-38410 is high with a CVSS score of 7.8.
AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are affected by CVE-2021-38410.
CVE-2021-38410 can be exploited by an attacker to gain control of one or more locations in the search path through DLL hijacking.
You can find more information about CVE-2021-38410 on the AVEVA and CISA websites.