CVE-2021-32979

AVEVA SuiteLink Server Null Pointer Dereference

Description

Null pointer dereference in SuiteLink server while processing commands 0x04/0x0a

Remediation

Solution:

  • AVEVA recommends organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Users with affected versions of these products should apply the corresponding security update. Note a subset of the updates requires activation-based licensing. Please see AVEVA security bulletin AVEVA-2021-003 for more information.

Category

7.5
CVSS
Severity: High
CVSS 3.1 •
CVSS 2.0 •
EPSS 0.46%
Vendor Advisory aveva.com
Affected: AVEVA Software, LLC AVEVA System Platform 2020
Affected: AVEVA Software, LLC AVEVA InTouch 2020
Affected: AVEVA Software, LLC AVEVA Historian 2020
Affected: AVEVA Software, LLC AVEVA Communication Drivers Pack 2020
Affected: AVEVA Software, LLC AVEVA Batch Management 2020
Affected: AVEVA Software, LLC AVEVA MES 2014
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2021-32979?
CVE-2021-32979 has been scored as a high severity vulnerability.
How to fix CVE-2021-32979?
To fix CVE-2021-32979: AVEVA recommends organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Users with affected versions of these products should apply the corresponding security update. Note a subset of the updates requires activation-based licensing. Please see AVEVA security bulletin AVEVA-2021-003 for more information.
Is CVE-2021-32979 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2021-32979 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2021-32979?
CVE-2021-32979 affects AVEVA Software, LLC AVEVA System Platform 2020, AVEVA Software, LLC AVEVA InTouch 2020, AVEVA Software, LLC AVEVA Historian 2020, AVEVA Software, LLC AVEVA Communication Drivers Pack 2020, AVEVA Software, LLC AVEVA Batch Management 2020, AVEVA Software, LLC AVEVA MES 2014.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.