7.1

CVE-2023-34982

AVEVA Operations Control Logger External Control of File Name or Path

This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Aveva ≫ Batch Management Version < 2020
Aveva ≫ Batch Management Version 2020 Update -
Aveva ≫ Batch Management Version 2020 Update sp1
Aveva ≫ Communication Drivers Version < 2020
Aveva ≫ Communication Drivers Version 2020 Update -
Aveva ≫ Communication Drivers Version 2020 Update r2
Aveva ≫ Communication Drivers Version 2020 Update r2_p01
Aveva ≫ Edge Version <= 20.1.101
Aveva ≫ Enterprise Licensing Version <= 3.7.002
Aveva ≫ Historian Version < 2020
Aveva ≫ Historian Version 2020 Update -
Aveva ≫ Historian Version 2020 Update r2
Aveva ≫ Historian Version 2020 Update r2_p01
Aveva ≫ Intouch Version < 2020
Aveva ≫ Intouch Version 2020 Update -
Aveva ≫ Intouch Version 2020 Update r2
Aveva ≫ Intouch Version 2020 Update r2_p01
Aveva ≫ Manufacturing Execution System Version 2020 Update p01
Aveva ≫ Mobile Operator Version < 2020
Aveva ≫ Mobile Operator Version 2020
Aveva ≫ Mobile Operator Version 2020 Update -
Aveva ≫ Mobile Operator Version 2020 Update r1
Aveva ≫ Plant Scada Version < 2020
Aveva ≫ Plant Scada Version 2020 Update -
Aveva ≫ Plant Scada Version 2020 Update r2
Aveva ≫ Recipe Management Version < 2020
Aveva ≫ Recipe Management Version 2020 Update -
Aveva ≫ Recipe Management Version 2020 Update update_1_patch_2
Aveva ≫ System Platform Version < 2020
Aveva ≫ System Platform Version 2020 Update -
Aveva ≫ System Platform Version 2020 Update r2
Aveva ≫ System Platform Version 2020 Update r2_p01
Aveva ≫ Telemetry Server Version 2020r2 Update -
Aveva ≫ Telemetry Server Version 2020r2 Update sp1
Aveva ≫ Work Tasks Version < 2020
Aveva ≫ Work Tasks Version 2020 Update -
Aveva ≫ Work Tasks Version 2020 Update update_1
Aveva ≫ Work Tasks Version 2020 Update update_2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.121
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
DHS.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-610 Externally Controlled Reference to a Resource in Another Sphere

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

CWE-73 External Control of File Name or Path

The product allows user input to control or influence paths or file names that are used in filesystem operations.

https://www.aveva.com/en/support-and-success/cyber-security-updates/
Vendor Advisory
https://www.cisa.gov/news-events/ics-advisories/icsa-23-318-01
Third Party Advisory
US Government Resource