The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location.
2021-06-09T17:15:07.737
2024-11-21T06:07:58.443
Modified
CVSSv3.1: 6.6 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | aveva | intouch_2017 | - | Yes |
| Application | aveva | intouch_2020 | - | Yes |
| Application | aveva | intouch_2020 | r2 | Yes |