CVE-2021-38410
AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.22%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.22% probability · 13th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-427
- Affected
- aveva/batch management · aveva/enterprise data management · aveva/manufacturing execution system · aveva/mobile operator · aveva/platform common services · aveva/system platform · aveva/work tasks
- Source
- ics-cert@hq.dhs.gov
References
- https://www.aveva.com/en/support-and-success/cyber-security-updates/Vendor Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-252-01Third Party Advisory, US Government Resource
- https://www.aveva.com/en/support-and-success/cyber-security-updates/Vendor Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-252-01Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.