AVEVA System Platform information disclosure | CVE-2022-0835
NAME
AVEVA System Platform information disclosure
- Platforms Affected:
AVEVA System Platform 2020 R2 P01
AVEVA System Platform 2020 R2S
AVEVA System Platform 2020 - Risk Level:
8.1 - Exploitability:
Unproven - Consequences:
Obtain Information
DESCRIPTION
AVEVA System Platform could allow a local authenticated attacker to obtain sensitive information, caused by cleartext storage of sensitive information in memory. An attacker could exploit this vulnerability to obtain user credentials and use this information to launch further attacks against the affected system.
CVSS 3.0 Information
- Privileges Required: Low
- User Interaction: Required
- Scope: Changed
- Access Vector: Local
- Access Complexity: Low
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: Low
- Remediation Level: Official Fix
MITIGATION
Upgrade to the latest version of AVEVA System Platform (2020 R2 SP1, 2020 P01, or later), available from the AVEVA Web site. See References.
- Reference Link:
https://www.cisa.gov/uscert/ics/advisories/icsa-22-067-02 - Reference Link:
https://www.aveva.com/en/products/system-platform/
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.