AVEVA PCS Portal Uncontrolled Search Path Element
Vulnerability Description
AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-38410
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Noam Moshe of Claroty discovered and disclosed the vulnerability to the AVEVA Software Security Response Center.
References
More from AVEVA
View All →Affected Vendor
AVEVA
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.