QID 591141
Date Published: 2022-10-26
QID 591141: AVEVA System Platform Sensitive Information Disclosure Vulnerability (ICSA-22-067-02)
AFFECTED PRODUCTS
The following versions of AVEVA System Platform, a software management platform, are affected:
AVEVA System Platform 2020 R2 P01
AVEVA System Platform 2020 R2
AVEVA System Platform 2020
QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys
Successful exploitation of this vulnerability could expose cleartext credentials for the network user account or for logged-in users to an authorized, low privilege user. The cleartext credentials would also be exposed if the user creates a diagnostic memory dump of the relevant process and saves it to a non-protected location where an unauthorized, malicious user can access it.
Customers are advised to refer to Schneider Electric MITIGATIONS section icsa-22-067-02 for affected packages and patching details.
- icsa-22-067-02 -
www.cisa.gov/uscert/ics/advisories/icsa-22-067-02
CVEs related to QID 591141
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| icsa-22-067-02 |
|