This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HAveva Batch Management
APPAveva2020< 2020Aveva Communication Drivers
APPAveva2020< 2020Aveva Edge
APPAveva≤ 20.1.101Aveva Enterprise Licensing
APPAveva≤ 3.7.002Aveva Historian
APPAveva2020< 2020Aveva Intouch
APPAveva2020< 2020Aveva Manufacturing Execution System
APPAveva2020< 2020Aveva Mobile Operator
APPAveva2020< 2020Aveva Plant Scada
APPAveva2020< 2020Aveva Recipe Management
APPAveva2020< 2020Aveva System Platform
APPAveva2020< 2020Aveva Telemetry Server
APPAveva2020r2Aveva Work Tasks
APPAveva2020< 2020
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoS
Related vulnerabilities
CVE-2021-42796CRITICAL9.8PL ✓same product
AVEVA Edge: nieuwierzytelnione zdalne wykonanie poleceń (RCE) w ExecuteCommand()
CVE-2023-1256CRITICAL9.8PL ✓same product
Nieprawidłowa autoryzacja w AVEVA Plant SCADA i Telemetry Server
CVE-2018-17914CRITICAL9.8PL ✓same product
RCE bez uwierzytelnienia w Aveva InduSoft Web Studio i InTouch Edge HMI
CVE-2018-17916CRITICAL9.8PL ✓same product
Stack-based buffer overflow i RCE w Aveva InduSoft Web Studio i InTouch Edge HMI
CVE-2023-6132HIGH7.3same product
The vulnerability, if exploited, could allow a malicious entity with access to the file system to achieve arb...