Cleartext storage of sensitive information in InTouch - CVE-2021-32942
Published: June 9, 2021
InTouch
AVEVA Software, LLC.
Description
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to the storage of user credentials in plain-text. A local user can create a diagnostic memory dump of the process, save it to a non-protected location and gain unauthorized access to sensitive information on the system.