← Vulnerability feed

Vulnerability record · CVE-2021-32977 · published 4 April 2022

CVE-2021-32977: Aveva system platform improper verification of cryptographic signature vulnerability

Aveva · System Platform

AVEVA System Platform versions 2017 through 2020 R2 P01 does not verify, or incorrectly verifies, the cryptographic signature for data.

7.2 CVSS 3.1 High EPSS 0.64% · top 51.2% CWE-347 · Improper verification of cryptographic signature
7.2CVSS 3.1 base score, v2 6.5
0.64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

AVEVA System Platform versions 2017 through 2020 R2 P01 does not verify, or incorrectly verifies, the cryptographic signature for data.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-32977 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-33008Aveva system platform missing authentication for critical function vulnerabilityAVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requires a provable user identity.EPSS 1.2%7.8CVE-2023-33873Aveva batch management execution with unnecessary privileges vulnerabilityThis privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privi…EPSS 0.24%7.8CVE-2021-38410Aveva batch management uncontrolled search path element vulnerabilityAVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled …EPSS 0.22%7.5CVE-2021-33010Aveva system platform vulnerabilityAn exception is thrown from a function in AVEVA System Platform versions 2017 through 2020 R2 P01, but it is not caught, which may cause a denial-of-…EPSS 1.1%7.2CVE-2021-32985Aveva system platform origin validation error vulnerabilityAVEVA System Platform versions 2017 through 2020 R2 P01 does not properly verify that the source of data or communication is valid.EPSS 0.50%7.2CVE-2021-32981Aveva system platform path traversal vulnerabilityAVEVA System Platform versions 2017 through 2020 R2 P01 uses external input to construct a pathname that is intended to identify a file or directory …EPSS 1.2%7.1CVE-2023-34982Aveva batch management vulnerabilityThis external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System pri…EPSS 0.22%5.5CVE-2022-0835Aveva system platform cleartext storage of sensitive data vulnerabilityAVEVA System Platform 2020 stores sensitive information in cleartext, which may allow access to an attacker or a low-privileged user.EPSS 0.17%

Source: NIST National Vulnerability Database (record CVE-2021-32977), CISA KEV, FIRST EPSS (scores of 2026-09-30). This page is refreshed as NVD updates the record.