CVE-2021-32959 – AVEVA SuiteLink Server Buffer Overflow
https://notcve.org/view.php?id=CVE-2021-32959
Heap-based buffer overflow in SuiteLink server while processing commands 0x05/0x06 Desbordamiento del búfer en la región heap de la memoria en SuiteLink server mientras se procesan los comandos 0x05/0x06 • https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2021-003.pdf • CWE-122: Heap-based Buffer Overflow •
CVE-2021-32963 – AVEVA SuiteLink Server Null Pointer Dereference
https://notcve.org/view.php?id=CVE-2021-32963
Null pointer dereference in SuiteLink server while processing commands 0x03/0x10 Una desreferencia de puntero null en SuiteLink server mientras se procesan los comandos 0x03/0x10 • https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2021-003.pdf • CWE-476: NULL Pointer Dereference •
CVE-2021-32942
https://notcve.org/view.php?id=CVE-2021-32942
The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location. La vulnerabilidad podría exponer credenciales en texto sin cifrar de AVEVA InTouch Runtime 2020 R2 y todas las versiones anteriores (WindowViewer) si un usuario autorizado privilegiado crea un volcado de memoria de diagnóstico del proceso y lo guarda en una ubicación no protegida • https://us-cert.cisa.gov/ics/advisories/icsa-21-159-03 https://www.aveva.com/en/support/cyber-security-updates • CWE-312: Cleartext Storage of Sensitive Information CWE-316: Cleartext Storage of Sensitive Information in Memory •
CVE-2020-13501
https://notcve.org/view.php?id=CVE-2020-13501
An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. Parameter InstanceName in CHaD.asmx is vulnerable to unauthenticated SQL injection attacks. Se presenta una vulnerabilidad de inyección SQL en la funcionalidad web service del archivo CHaD.asmx de eDNA Enterprise Data Historian versión 3.0.1.2/7.5.4989.33053. Unas peticiones web SOAP especialmente diseñadas pueden causar inyecciones SQL resultando en un compromiso de los datos. • https://talosintelligence.com/vulnerability_reports/TALOS-2020-1106 https://us-cert.cisa.gov/ics/advisories/icsa-20-254-01 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2020-13500
https://notcve.org/view.php?id=CVE-2020-13500
SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. Parameter ClassName in CHaD.asmx is vulnerable to unauthenticated SQL injection attacks. Se presenta una vulnerabilidad de inyección SQL en la funcionalidad web service del archivo CHaD.asmx de eDNA Enterprise Data Historian versión 3.0.1.2/7.5.4989.33053. Unas peticiones web SOAP especialmente diseñadas pueden causar inyecciones SQL resultando en un compromiso de los datos. • https://talosintelligence.com/vulnerability_reports/TALOS-2020-1106 https://us-cert.cisa.gov/ics/advisories/icsa-20-254-01 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •