High severity7.3NVD Advisory· Published Jul 27, 2022· Updated Jun 17, 2026
CVE-2021-38410
CVE-2021-38410
Description
AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
16- cpe:2.3:a:aveva:batch_management:2020:*:*:*:*:*:*:*
- cpe:2.3:a:aveva:enterprise_data_management:2020:*:*:*:*:*:*:*
- cpe:2.3:a:aveva:manufacturing_execution_system:2020:*:*:*:*:*:*:*
- cpe:2.3:a:aveva:mobile_operator:2020:*:*:*:*:*:*:*
cpe:2.3:a:aveva:platform_common_services:4.4.6:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:aveva:platform_common_services:4.4.6:*:*:*:*:*:*:*
- cpe:2.3:a:aveva:platform_common_services:4.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:aveva:platform_common_services:4.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:aveva:platform_common_services:4.5.2:*:*:*:*:*:*:*
cpe:2.3:a:aveva:system_platform:2020:-:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:aveva:system_platform:2020:-:*:*:*:*:*:*
- cpe:2.3:a:aveva:system_platform:2020:r2:*:*:*:*:*:*
- cpe:2.3:a:aveva:system_platform:2020:r2_p01:*:*:*:*:*:*
cpe:2.3:a:aveva:work_tasks:2020:-:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:aveva:work_tasks:2020:-:*:*:*:*:*:*
- cpe:2.3:a:aveva:work_tasks:2020:update_1:*:*:*:*:*:*
- Range: <=4.5.2, 4.5.1, 4.5.0, and 4.4.6
<=4.5.2, 4.5.1, 4.5.0, 4.4.6+ 1 more
- (no CPE)range: <=4.5.2, 4.5.1, 4.5.0, 4.4.6
- (no CPE)range: 4.5.2
Patches
Vulnerability mechanics
References
2- www.aveva.com/en/support-and-success/cyber-security-updates/nvdVendor Advisory
- www.cisa.gov/uscert/ics/advisories/icsa-21-252-01nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.