CVE-2021-32942

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
09/06/2021
Last modified:
25/10/2022

Description

The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:aveva:intouch_2017:-:update3:*:*:*:*:*:*
cpe:2.3:a:aveva:intouch_2020:-:*:*:*:*:*:*:*
cpe:2.3:a:aveva:intouch_2020:r2:*:*:*:*:*:*:*