7.8

CVE-2023-33873

This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AvevaBatch Management Version < 2020
AvevaBatch Management Version2020 Update-
AvevaBatch Management Version2020 Updatesp1
AvevaCommunication Drivers Version < 2020
AvevaCommunication Drivers Version2020 Update-
AvevaCommunication Drivers Version2020 Updater2
AvevaCommunication Drivers Version2020 Updater2_p01
AvevaEdge Version <= 20.1.101
AvevaEnterprise Licensing Version <= 3.7.002
AvevaHistorian Version < 2020
AvevaHistorian Version2020 Update-
AvevaHistorian Version2020 Updater2
AvevaHistorian Version2020 Updater2_p01
AvevaIntouch Version < 2020
AvevaIntouch Version2020 Update-
AvevaIntouch Version2020 Updater2
AvevaIntouch Version2020 Updater2_p01
AvevaManufacturing Execution System Version2020 Updatep01
AvevaMobile Operator Version < 2020
AvevaMobile Operator Version2020
AvevaMobile Operator Version2020 Update-
AvevaMobile Operator Version2020 Updater1
AvevaPlant Scada Version < 2020
AvevaPlant Scada Version2020 Update-
AvevaPlant Scada Version2020 Updater2
AvevaRecipe Management Version < 2020
AvevaRecipe Management Version2020 Update-
AvevaRecipe Management Version2020 Updateupdate_1_patch_2
AvevaSystem Platform Version < 2020
AvevaSystem Platform Version2020 Update-
AvevaSystem Platform Version2020 Updater2
AvevaSystem Platform Version2020 Updater2_p01
AvevaTelemetry Server Version2020r2 Update-
AvevaTelemetry Server Version2020r2 Updatesp1
AvevaWork Tasks Version < 2020
AvevaWork Tasks Version2020 Update-
AvevaWork Tasks Version2020 Updateupdate_1
AvevaWork Tasks Version2020 Updateupdate_2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.346
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ics-cert@hq.dhs.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-250 Execution with Unnecessary Privileges

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.