Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location.

CVSS 1 Total

ScoreSeverityVersionVector String
6.6MEDIUM3.1CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Product Status

Learn more

Versions 1 Total

Default Status: unknown

affected

Credits

  • Ilya Karpov, Evgeniy Druzhinin, and Konstantin Kondratev of Rostelecom-Solar reported this vulnerability to AVEVA.

Updated:

This container includes required additional information provided by the CVE Program for this vulnerability.