AVEVA has an update available to handle multiple vulnerabilities in its Edge, according to a report with CISA.

The vulnerabilities are uncontrolled search path element, exposure of sensitive information to an unauthorized actor, uncontrolled resource consumption, improper access control, and Windows UNC share.

Successful exploitation of these remotely exploitable vulnerabilities, discovered by Sam Hanson of Dragos, could allow an attacker to insert malicious DLL files and trick the application into executing code.

The following versions of AVEVA Edge, an HMI/SCADA software, suffer from the vulnerabilities:

  • AVEVA Edge 2020 R2 SP1
  • AVEVA Edge 2020 R2 SP1 w/ HF 2020.2.00.40
  • AVEVA Edge 2020 R2 and all prior versions (formerly known as InduSoft Web Studio)

In one issue, in AVEVA Edge versions R2020 and prior could allow a malicious entity with access to the file system to achieve arbitrary code execution and privilege escalation by tricking the AVEVA Edge InstallShield package to load an unsafe DLL. This attack is only possible during the installation or when performing an install or repair operation.

Schneider Bold

CVE-2016-2542 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.8.

In addition, AVEVA Edge versions R2020 and prior could allow internal network scanning and expose sensitive device information.

CVE-2021-42794 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 5.3.

Also, AVEVA Edge versions R2020 and prior could allow unauthenticated arbitrary commands to be executed with the security context of the StADOSvr.exe process. In most instances, this will be a standard-privileged user account under which the AVEVA Edge runtime was started. It’s possible for a high-privileged service account to have been configured and assigned for running AVEVA Edge runtime.

CVE-2021-42796 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 9.8.

In another issue, AVEVA Edge versions R2020 and prior could allow an unauthenticated actor to trick the AVEVA Edge runtime into disclosing a Windows access token of the user account configured for accessing external DB resources.

CVE-2021-42797 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 8.6.

The product sees use mainly in the critical manufacturing sector, and on a global basis.

No known public exploits specifically target these vulnerabilities. However, an attacker with low skill level could leverage this low complexity vulnerability.

AVEVA recommends organizations evaluate the impact of these vulnerabilities based on operational environment, architecture, and product implementations.

In terms of mitigations, AVEVA added:

  • Users of AVEV Edge (formerly known as InduSoft Web Studio) up to 2020 R2 SP1 w/HF 2020.2.00.40 should apply AVEVA Edge 2020 R2 SP2 as soon as possible 
  • Restrict access to port TCP/3997
ISSSource

Pin It on Pinterest

Share This