CVE-2021-38410

HIGH

AVEVA Platform Common Services Portal 4.4.6-4.5.2 - DLL Hijacking via Uncontrolled Search Path Element

Title source: llm
STIX 2.1

Description

AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource x_refsource_confirm
https://www.cisa.gov/uscert/ics/advisories/icsa-21-252-01

Scores

CVSS v3 7.3
EPSS 0.0021
EPSS Percentile 11.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (10)
aveva/batch_management 2020
aveva/enterprise_data_management 2020
aveva/manufacturing_execution_system 2020
aveva/mobile_operator 2020
aveva/platform_common_services 4.4.6
aveva/platform_common_services 4.5.0
aveva/platform_common_services 4.5.1
aveva/platform_common_services 4.5.2
aveva/system_platform 2020 (3 CPE variants)
aveva/work_tasks 2020 (2 CPE variants)
Published Jul 27, 2022
Tracked Since Feb 18, 2026