9.8

CVE-2023-1256

The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AvevaAveva Plant Scada Version2020r2 Update-
AvevaAveva Plant Scada Version2020r2 Updateupdate_10
AvevaAveva Plant Scada Version2023 Update-
AvevaAveva Plant Scada Version2023 Updateupdate_10
AvevaTelemetry Server Version2020r2 Update-
AvevaTelemetry Server Version2020r2 Updatesp1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.319
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ics-cert@hq.dhs.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H