![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-32999 – AVEVA SuiteLink Server Improper Handling of Exceptional Conditions
https://notcve.org/view.php?id=CVE-2021-32999
23 Sep 2021 — Improper handling of exceptional conditions in SuiteLink server while processing command 0x01 Un manejo inapropiado de condiciones excepcionales en SuiteLink server mientras se procesa el comando 0x01 • https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2021-003.pdf • CWE-755: Improper Handling of Exceptional Conditions •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-32979 – AVEVA SuiteLink Server Null Pointer Dereference
https://notcve.org/view.php?id=CVE-2021-32979
23 Sep 2021 — Null pointer dereference in SuiteLink server while processing commands 0x04/0x0a Una desreferencia de puntero null en SuiteLink server mientras se procesan los comandos 0x04/0x0a • https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2021-003.pdf • CWE-476: NULL Pointer Dereference •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-32971 – AVEVA SuiteLink Server Null Pointer Dereference
https://notcve.org/view.php?id=CVE-2021-32971
23 Sep 2021 — Null pointer dereference in SuiteLink server while processing command 0x07 Una desreferencia de puntero null en SuiteLink server mientras se procesa el comando 0x07 • https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2021-003.pdf • CWE-476: NULL Pointer Dereference •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-32959 – AVEVA SuiteLink Server Buffer Overflow
https://notcve.org/view.php?id=CVE-2021-32959
23 Sep 2021 — Heap-based buffer overflow in SuiteLink server while processing commands 0x05/0x06 Desbordamiento del búfer en la región heap de la memoria en SuiteLink server mientras se procesan los comandos 0x05/0x06 • https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2021-003.pdf • CWE-122: Heap-based Buffer Overflow •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-32963 – AVEVA SuiteLink Server Null Pointer Dereference
https://notcve.org/view.php?id=CVE-2021-32963
23 Sep 2021 — Null pointer dereference in SuiteLink server while processing commands 0x03/0x10 Una desreferencia de puntero null en SuiteLink server mientras se procesan los comandos 0x03/0x10 • https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2021-003.pdf • CWE-476: NULL Pointer Dereference •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-32942
https://notcve.org/view.php?id=CVE-2021-32942
09 Jun 2021 — The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location. La vulnerabilidad podría exponer credenciales en texto sin cifrar de AVEVA InTouch Runtime 2020 R2 y todas las versiones anteriores (WindowViewer) si un usuario autorizado privilegiado crea un volcado de memoria de diagnóstico del proceso y lo guarda en una ubic... • https://us-cert.cisa.gov/ics/advisories/icsa-21-159-03 • CWE-312: Cleartext Storage of Sensitive Information CWE-316: Cleartext Storage of Sensitive Information in Memory •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-13501
https://notcve.org/view.php?id=CVE-2020-13501
24 Sep 2020 — An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. Parameter InstanceName in CHaD.asmx is vulnerable to unauthenticated SQL injection attacks. Se presenta una vulnerabilidad de inyección SQL en la funcionalidad web service del archivo CHaD.asmx de eDNA Enterprise Data Historian versión 3.0.1.2/7.5.4989.33053. Unas peticiones w... • https://talosintelligence.com/vulnerability_reports/TALOS-2020-1106 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-13500
https://notcve.org/view.php?id=CVE-2020-13500
24 Sep 2020 — SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. Parameter ClassName in CHaD.asmx is vulnerable to unauthenticated SQL injection attacks. Se presenta una vulnerabilidad de inyección SQL en la funcionalidad web service del archivo CHaD.asmx de eDNA Enterprise Data Historian versión 3.0.1.2/7.5.4989.33053. Unas peticiones web SOA... • https://talosintelligence.com/vulnerability_reports/TALOS-2020-1106 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-13499
https://notcve.org/view.php?id=CVE-2020-13499
24 Sep 2020 — An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. Parameter InstancePath in CHaD.asmx is vulnerable to unauthenticated SQL injection attacks. Se presenta una vulnerabilidad de inyección SQL en la funcionalidad web service del archivo CHaD.asmx de eDNA Enterprise Data Historian versión 3.0.1.2/7.5.4989.33053. Unas peticiones w... • https://talosintelligence.com/vulnerability_reports/TALOS-2020-1106 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-13505
https://notcve.org/view.php?id=CVE-2020-13505
24 Sep 2020 — Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unauthenticated HTTP requests to trigger this vulnerability. El parámetro psClass en el archivo ednareporting.asmx, es vulnerable a ataques de inyección SQL no autenticados. Unas peticiones web SOAP especialmente diseñadas pueden causar inyecciones SQL resultando en un compromiso de los datos. • https://talosintelligence.com/vulnerability_reports/TALOS-2020-1108 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •