#VU54466 Missing Authentication for Critical Function in AVEVA System Platform


Published: 2021-06-30

Vulnerability identifier: #VU54466

Vulnerability risk: Low

CVSSv3.1: 7 [CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-33008

CWE-ID: CWE-306

Exploitation vector: Local network

Exploit availability: No

Vulnerable software:
AVEVA System Platform
Server applications / SCADA systems

Vendor: AVEVA Software, LLC.

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the affected software does not perform any authentication for functionality that requires a provable user identity. A remote authenticated attacker on the local network can gain access to target system.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

AVEVA System Platform: 2017 U3 SP1 P01 - 2020 R2 P01


External links
http://ics-cert.us-cert.gov/advisories/icsa-21-180-05


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability