CVE Database
/

CVE-2023-34982

Back to search

CVE-2023-34982

Published: Nov 15, 2023

Modified: Aug 2, 2024

PUBLISHED

CVSS v3.1

5.5

MEDIUM

Description

This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.

VendorProductVersions

AVEVA

SystemPlatform

affected
0 - <= 2020 R2 SP1 P01

AVEVA

Historian

affected
0 - <= 2020 R2 SP1 P01

AVEVA

Application Server

affected
0 - <= 2020 R2 SP1 P01

AVEVA

InTouch

affected
0 - <= 2020 R2 SP1 P01

AVEVA

Enterprise Licensing (formerly known as License Manager)

affected
0 - <= 3.7.002

AVEVA

Manufacturing Execution System (formerly known as Wonderware MES)

affected
0 - <= 2020 P01

AVEVA

Recipe Management

affected
0 - <= 2020 R2 Update 1 Patch 2

AVEVA

Batch Management

affected
0 - <= 2020 SP1

AVEVA

Edge (formerly known as Indusoft Web Studio)

affected
0 - <= 2020 R2 SP1 P01

AVEVA

Worktasks (formerly known as Workflow Management)

affected
0 - <= 2020 U2

AVEVA

Plant SCADA (formerly known as Citect)

affected
0 - <= 2020 R2 Update 15

AVEVA

Mobile Operator (formerly known as IntelaTrac Mobile Operator Rounds)

affected
0 - <= 2020 R1

AVEVA

Communication Drivers Pack

affected
0 - <= 2020 R2 SP1

AVEVA

Telemetry Server

affected
0 - <= 2020 R2 SP1

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now