Lucene search

K
nvd[email protected]NVD:CVE-2021-32942
HistoryJun 09, 2021 - 5:15 p.m.

CVE-2021-32942

2021-06-0917:15:07
CWE-316
CWE-312
web.nvd.nist.gov
3
vulnerability
cleartext credentials
aveva intouch runtime
windowsviewer
authorized user
privileged user
diagnostic memory dump

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

10.4%

The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location.

Affected configurations

Nvd
Node
avevaintouch_2017Match-update3
OR
avevaintouch_2020Match-
OR
avevaintouch_2020Matchr2
VendorProductVersionCPE
avevaintouch_2017-cpe:2.3:a:aveva:intouch_2017:-:update3:*:*:*:*:*:*
avevaintouch_2020-cpe:2.3:a:aveva:intouch_2020:-:*:*:*:*:*:*:*
avevaintouch_2020r2cpe:2.3:a:aveva:intouch_2020:r2:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

10.4%

Related for NVD:CVE-2021-32942