CVE-2021-32942
Last modified
CVE-2021-32942 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Aveva | Intouch 2017 | All versions | Update3 |
| Aveva | Intouch 2020 | All versions | — |
| Aveva | Intouch 2020 | r2 | — |
References
- https://us-cert.cisa.gov/ics/advisories/icsa-21-159-03Patch, Third Party Advisory, US Government Resource
- https://www.aveva.com/en/support/cyber-security-updates/Patch, Vendor Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-159-03Patch, Third Party Advisory, US Government Resource
- https://www.aveva.com/en/support/cyber-security-updates/Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-32942?
How severe is CVE-2021-32942?
How do I fix CVE-2021-32942?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-32937An attacker can gain knowledge of a session temporary workin…7.5
- CVE-2021-32938Drawings SDK (All versions prior to 2022.4) are vulnerable t…7.1
- CVE-2021-32939FATEK Automation FvDesigner, Versions 1.5.88 and prior is vu…7.8
- CVE-2021-3294CASAP Automated Enrollment System 1.0 is affected by cross-s…5.4
- CVE-2021-32940An out-of-bounds read issue exists in the DWG file-recoverin…7.1
- CVE-2021-32941Annke N48PBB (Network Video Recorder) products of version 3.…9.8
- CVE-2021-32943The affected product is vulnerable to a stack-based buffer o…9.8
- CVE-2021-32944A use-after-free issue exists in the DGN file-reading proced…7.8
- CVE-2021-32945An attacker could decipher the encryption and gain access to…7.5
- CVE-2021-32946An improper check for unusual or exceptional conditions issu…7.8
- CVE-2021-32947FATEK Automation FvDesigner, Versions 1.5.88 and prior is vu…7.8
- CVE-2021-32948An out-of-bounds write issue exists in the DWG file-reading …7.8
Are you affected by CVE-2021-32942?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
