Lucene search

K
cve[email protected]CVE-2023-1256
HistoryMar 16, 2023 - 7:15 p.m.

CVE-2023-1256

2023-03-1619:15:18
web.nvd.nist.gov
32
cve
aveva
plant scada
telemetry server
vulnerability
authorization
exploit
unauthenticated user
denial of service
data tampering

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.2 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.9%

The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.

Affected configurations

NVD
Node
avevaaveva_plant_scadaMatch2020r2-
OR
avevaaveva_plant_scadaMatch2020r2update_10
OR
avevaaveva_plant_scadaMatch2023-
OR
avevaaveva_plant_scadaMatch2023update_10
OR
avevatelemetry_serverMatch2020r2-
OR
avevatelemetry_serverMatch2020r2sp1

CNA Affected

[
  {
    "vendor": "AVEVA",
    "product": "AVEVA Plant SCADA",
    "versions": [
      {
        "status": "affected",
        "version": "2023 Update 10"
      }
    ]
  },
  {
    "vendor": "AVEVA",
    "product": "AVEVA Plant SCADA",
    "versions": [
      {
        "status": "affected",
        "version": "2020R2 Update 10"
      }
    ]
  },
  {
    "vendor": "AVEVA",
    "product": "AVEVA Telemetry Server",
    "versions": [
      {
        "status": "affected",
        "version": "2020 R2 SP1"
      }
    ]
  }
]

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.2 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.9%

Related for CVE-2023-1256