7.8
CVE-2023-33873
- EPSS 0.24%
- Veröffentlicht 15.11.2023 17:15:41
- Zuletzt bearbeitet 21.11.2024 08:06:06
- Erkennungen
AVEVA Operations Control Logger Execution with Unnecessary Privileges
This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Aveva ≫ Batch Management Version < 2020
Aveva ≫ Batch Management Version 2020 Update -
Aveva ≫ Batch Management Version 2020 Update sp1
Aveva ≫ Communication Drivers Version < 2020
Aveva ≫ Communication Drivers Version 2020 Update -
Aveva ≫ Communication Drivers Version 2020 Update r2
Aveva ≫ Communication Drivers Version 2020 Update r2_p01
Aveva ≫ Enterprise Licensing Version <= 3.7.002
Aveva ≫ Manufacturing Execution System Version < 2020
Aveva ≫ Manufacturing Execution System Version 2020
Aveva ≫ Manufacturing Execution System Version 2020 Update p01
Aveva ≫ Mobile Operator Version < 2020
Aveva ≫ Mobile Operator Version 2020
Aveva ≫ Mobile Operator Version 2020 Update -
Aveva ≫ Mobile Operator Version 2020 Update r1
Aveva ≫ Plant Scada Version < 2020
Aveva ≫ Plant Scada Version 2020 Update -
Aveva ≫ Plant Scada Version 2020 Update r2
Aveva ≫ Recipe Management Version < 2020
Aveva ≫ Recipe Management Version 2020 Update -
Aveva ≫ Recipe Management Version 2020 Update update_1_patch_2
Aveva ≫ System Platform Version < 2020
Aveva ≫ System Platform Version 2020 Update -
Aveva ≫ System Platform Version 2020 Update r2
Aveva ≫ System Platform Version 2020 Update r2_p01
Aveva ≫ Telemetry Server Version 2020r2 Update -
Aveva ≫ Telemetry Server Version 2020r2 Update sp1
Aveva ≫ Work Tasks Version < 2020
Aveva ≫ Work Tasks Version 2020 Update -
Aveva ≫ Work Tasks Version 2020 Update update_1
Aveva ≫ Work Tasks Version 2020 Update update_2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.143 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| DHS.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-250 Execution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
https://www.aveva.com/en/support-and-success/cyber-security-updates/
https://www.cisa.gov/news-events/ics-advisories/icsa-23-318-01