AVEVA System Platform Cleartext Storage of Sensitive Information in Memory
CVE-2022-0835

8.1HIGH

Key Information:

Vendor

Aveva

Vendor
CVE Published:
11 April 2022

What is CVE-2022-0835?

AVEVA System Platform 2020 stores sensitive information in cleartext, which may allow access to an attacker or a low-privileged user.

Affected Version(s)

AVEVA System Platform 5.59 2020 R2 P01

AVEVA System Platform 2020 R2S

AVEVA System Platform 2020

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Noam Moshe of Claroty and Ilya Karpov, Evgeniy Druzhinin, and Konstantin Kondratev of Rostelecom-Solar reported this vulnerability to AVEVA.
.
CVE-2022-0835 : AVEVA System Platform Cleartext Storage of Sensitive Information in Memory