CVE-2021-38410

AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:aveva:system_platform:2020:r2_p01:*:*:*:*:*:*
cpe:2.3:a:aveva:system_platform:2020:r2:*:*:*:*:*:*
cpe:2.3:a:aveva:system_platform:2020:-:*:*:*:*:*:*
cpe:2.3:a:aveva:platform_common_services:4.5.2:*:*:*:*:*:*:*
cpe:2.3:a:aveva:platform_common_services:4.5.1:*:*:*:*:*:*:*
cpe:2.3:a:aveva:platform_common_services:4.5.0:*:*:*:*:*:*:*
cpe:2.3:a:aveva:platform_common_services:4.4.6:*:*:*:*:*:*:*
cpe:2.3:a:aveva:batch_management:2020:*:*:*:*:*:*:*
cpe:2.3:a:aveva:enterprise_data_management:2020:*:*:*:*:*:*:*
cpe:2.3:a:aveva:manufacturing_execution_system:2020:*:*:*:*:*:*:*
cpe:2.3:a:aveva:mobile_operator:2020:*:*:*:*:*:*:*
cpe:2.3:a:aveva:work_tasks:2020:-:*:*:*:*:*:*
cpe:2.3:a:aveva:work_tasks:2020:update_1:*:*:*:*:*:*

History

17 Apr 2025, 16:15

Type Values Removed Values Added
References (CONFIRM) https://www.cisa.gov/uscert/ics/advisories/icsa-21-252-01 - Third Party Advisory, US Government Resource () https://www.cisa.gov/uscert/ics/advisories/icsa-21-252-01 - Third Party Advisory, US Government Resource
References (CONFIRM) https://www.aveva.com/en/support-and-success/cyber-security-updates/ - Vendor Advisory () https://www.aveva.com/en/support-and-success/cyber-security-updates/ - Vendor Advisory

Information

Published : 2022-07-27 21:15

Updated : 2025-04-17 16:15


NVD link : CVE-2021-38410

Mitre link : CVE-2021-38410


JSON object : View

Products Affected

aveva

  • platform_common_services
  • enterprise_data_management
  • work_tasks
  • system_platform
  • manufacturing_execution_system
  • batch_management
  • mobile_operator
CWE
CWE-427

Uncontrolled Search Path Element