CVE-2021-38410
AVEVA PCS Portal Uncontrolled Search Path Element
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.3EPSS 0.2%KEV nãoPoC —Patch —
Lifecycle
Jul 27, 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Affected products
AVEVA · Platform Common Services (PCS) PortalWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →