PT-2021-19988 · Aveva · Aveva Intouch Runtime

Evgeniy Druzhinin

+2

·

Published

2021-06-09

·

Updated

2022-10-25

·

CVE-2021-32942

CVSS v3.1

6.6

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions AVEVA InTouch Runtime versions prior to 2020 R2
Description The issue could expose cleartext credentials if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location.
Recommendations For versions prior to 2020 R2, ensure that diagnostic memory dumps are saved to protected locations to prevent unauthorized access to cleartext credentials. As a temporary workaround, consider restricting access to the diagnostic memory dump feature until a patch is available.

Fix

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2021-32942

Affected Products

Aveva Intouch Runtime