CVE Database
/

CVE-2023-1256

Back to search

CVE-2023-1256

Published: Mar 16, 2023

Modified: Jan 16, 2025

PUBLISHED

CVSS v3.1

9.8

CRITICAL

Description

The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.

VendorProductVersions

AVEVA

AVEVA Plant SCADA

affected
2023 Update 10

AVEVA

AVEVA Plant SCADA

affected
2020R2 Update 10

AVEVA

AVEVA Telemetry Server

affected
2020 R2 SP1

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2023-1256 | CRITICAL (9.8) - Security Vulnerability | QwikSec