9.8
CVE-2023-1256
- EPSS 0.68%
- Veröffentlicht 16.03.2023 19:15:18
- Zuletzt bearbeitet 21.11.2024 07:38:46
- Erkennungen
CVE-2023-1256
The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Aveva ≫ Aveva Plant Scada Version 2020r2 Update -
Aveva ≫ Aveva Plant Scada Version 2020r2 Update update_10
Aveva ≫ Aveva Plant Scada Version 2023 Update -
Aveva ≫ Aveva Plant Scada Version 2023 Update update_10
Aveva ≫ Telemetry Server Version 2020r2 Update -
Aveva ≫ Telemetry Server Version 2020r2 Update sp1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.68% | 0.474 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| DHS.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://www.cisa.gov/news-events/ics-advisories/icsa-23-073-04