AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-24862 AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.
Fixes

Solution

AVEVA recommends organizations evaluate the impact of this vulnerability based on their operational environment, architecture, and product implementation. Users of affected versions of the products should apply the corresponding security update as soon as possible. Security update PCS 4.5.3 is available for the following versions: AVEVA Mobile Operator 2020 AVEVA Enterprise Data Management 2021 AVEVA System Platform 2020 R2 P01 AVEVA System Platform 2020 R2 AVEVA Work Tasks 2020 Update 1 Security update PCS 4.4.7 is available for the following versions: AVEVA System Platform 2020 AVEVA Work Tasks 2020 AVEVA Manufacturing Execution System 2020 AVEVA Batch Management 2020 For more information on this issue, including security updates, please see Security Bulletin AVEVA-2021-008.


Workaround

No workaround given by the vendor.

History

Thu, 17 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-04-17T15:49:43.702Z

Reserved: 2021-08-10T00:00:00.000Z

Link: CVE-2021-38410

cve-icon Vulnrichment

Updated: 2024-08-04T01:37:16.647Z

cve-icon NVD

Status : Modified

Published: 2022-07-27T21:15:08.523

Modified: 2025-04-17T16:15:23.570

Link: CVE-2021-38410

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.