QID 591141

Date Published: 2022-10-26

QID 591141: AVEVA System Platform Sensitive Information Disclosure Vulnerability (ICSA-22-067-02)

AFFECTED PRODUCTS
The following versions of AVEVA System Platform, a software management platform, are affected:
AVEVA System Platform 2020 R2 P01
AVEVA System Platform 2020 R2
AVEVA System Platform 2020

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys

Successful exploitation of this vulnerability could expose cleartext credentials for the network user account or for logged-in users to an authorized, low privilege user. The cleartext credentials would also be exposed if the user creates a diagnostic memory dump of the relevant process and saves it to a non-protected location where an unauthorized, malicious user can access it.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Low - 1.9 severity.
  • Solution

    Customers are advised to refer to Schneider Electric MITIGATIONS section icsa-22-067-02 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591141

    Software Advisories
    Advisory ID Software Component Link
    icsa-22-067-02 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-067-02