Insecure DLL loading in AVEVA Software, LLC. products - CVE-2021-38410

 

Insecure DLL loading in AVEVA Software, LLC. products - CVE-2021-38410

Published: September 10, 2021


Vulnerability identifier: #VU56440
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-38410
CWE-ID: CWE-427
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise vulnerable system.

The vulnerability exists due to the application loads DLL libraries in an insecure manner. A local user can control one or more locations in the search path.


Affected software

Platform Common Services (PCS) Portal
AVEVA Batch Management
AVEVA Mobile Operator
AVEVA Manufacturing Execution System
AVEVA Work Tasks
AVEVA Enterprise Data Management
AVEVA System Platform

How to mitigate CVE-2021-38410

Install updates from vendor's website.

Platform Common Services (PCS) Portal - addressed in versions 4.4.7, 4.5.3

External References

Related Security Bulletins