9.8

CVE-2023-1256

CVE-2023-1256

The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Aveva ≫ Aveva Plant Scada Version 2020r2 Update -
Aveva ≫ Aveva Plant Scada Version 2020r2 Update update_10
Aveva ≫ Aveva Plant Scada Version 2023 Update -
Aveva ≫ Aveva Plant Scada Version 2023 Update update_10
Aveva ≫ Telemetry Server Version 2020r2 Update -
Aveva ≫ Telemetry Server Version 2020r2 Update sp1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.68% 0.474
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
DHS.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://www.cisa.gov/news-events/ics-advisories/icsa-23-073-04
Third Party Advisory
US Government Resource