CVE Published: 09/06/2021 |
CVE Updated: 17/09/2024 |
CVE Year: 2021 Source: icscert |
Vendor: AVEVA |
Product: InTouch Status : PUBLISHED
CVE-2021-32942 Description
The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location.
Metrics
CVSS Version: 3.1 |
Base Score: 6.6 MEDIUM Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N