7.1

CVE-2023-34982

This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.

Data is provided by the National Vulnerability Database (NVD)
AvevaBatch Management Version < 2020
AvevaBatch Management Version2020 Update-
AvevaBatch Management Version2020 Updatesp1
AvevaCommunication Drivers Version < 2020
AvevaCommunication Drivers Version2020 Update-
AvevaCommunication Drivers Version2020 Updater2
AvevaCommunication Drivers Version2020 Updater2_p01
AvevaEdge Version <= 20.1.101
AvevaEnterprise Licensing Version <= 3.7.002
AvevaHistorian Version < 2020
AvevaHistorian Version2020 Update-
AvevaHistorian Version2020 Updater2
AvevaHistorian Version2020 Updater2_p01
AvevaIntouch Version < 2020
AvevaIntouch Version2020 Update-
AvevaIntouch Version2020 Updater2
AvevaIntouch Version2020 Updater2_p01
AvevaManufacturing Execution System Version2020 Updatep01
AvevaMobile Operator Version < 2020
AvevaMobile Operator Version2020
AvevaMobile Operator Version2020 Update-
AvevaMobile Operator Version2020 Updater1
AvevaPlant Scada Version < 2020
AvevaPlant Scada Version2020 Update-
AvevaPlant Scada Version2020 Updater2
AvevaRecipe Management Version < 2020
AvevaRecipe Management Version2020 Update-
AvevaRecipe Management Version2020 Updateupdate_1_patch_2
AvevaSystem Platform Version < 2020
AvevaSystem Platform Version2020 Update-
AvevaSystem Platform Version2020 Updater2
AvevaSystem Platform Version2020 Updater2_p01
AvevaTelemetry Server Version2020r2 Update-
AvevaTelemetry Server Version2020r2 Updatesp1
AvevaWork Tasks Version < 2020
AvevaWork Tasks Version2020 Update-
AvevaWork Tasks Version2020 Updateupdate_1
AvevaWork Tasks Version2020 Updateupdate_2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.09% 0.266
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
ics-cert@hq.dhs.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-610 Externally Controlled Reference to a Resource in Another Sphere

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

CWE-73 External Control of File Name or Path

The product allows user input to control or influence paths or file names that are used in filesystem operations.