VulnerabilityModified
CVE-2021-32942
The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location.
MEDIUM 5.5EPSS 0.18%
Does this matter?
Lower severity and a low EPSS score (0.18%). Track it; it rarely justifies an emergency change on its own.
Description
The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.18% probability · 8th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-316, CWE-312
- Affected
- aveva/intouch 2017 · aveva/intouch 2020
- Source
- ics-cert@hq.dhs.gov
References
- https://us-cert.cisa.gov/ics/advisories/icsa-21-159-03Patch, Third Party Advisory, US Government Resource
- https://www.aveva.com/en/support/cyber-security-updates/Patch, Vendor Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-159-03Patch, Third Party Advisory, US Government Resource
- https://www.aveva.com/en/support/cyber-security-updates/Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.