QID 590589

Date Published: 2021-11-25

QID 590589: AVEVA SuiteLink Server Multiple Vulnerabilities (ICSA-21-231-01)

AFFECTED PRODUCTS
AVEVA reports the following products ship a vulnerable version of the SuiteLink Server and are affected:
AVEVA InTouch 2020 R2 P01 and all prior versions
AVEVA Historian 2020 R2 P01 and all prior versions
AVEVA Communication Drivers Pack 2020 R2 and all prior versions
AVEVA Operations Integration Core 3.0 and all prior versions
AVEVA Batch Management 2020 and all prior versionsP>QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys

Successful exploitation of these vulnerabilities could cause the SuiteLink Server to crash. It may be possible to achieve remote code execution, but no proof-of-concept currently exists.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-231-01 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-231-01 URL Logo www.us-cert.gov/ics/advisories/ICSA-21-231-01