Lucene search

K
cve[email protected]CVE-2023-33873
HistoryNov 15, 2023 - 5:15 p.m.

CVE-2023-33873

2023-11-1517:15:41
CWE-250
web.nvd.nist.gov
31
cve-2023-33873
privilege escalation
vulnerability
os authentication

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.8 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.2%

This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine.

Affected configurations

NVD
Node
avevabatch_managementRange<2020
OR
avevabatch_managementMatch2020-
OR
avevabatch_managementMatch2020sp1
OR
avevacommunication_driversRange<2020
OR
avevacommunication_driversMatch2020-
OR
avevacommunication_driversMatch2020r2
OR
avevacommunication_driversMatch2020r2_p01
OR
avevaedgeRange≀20.1.101
OR
avevaenterprise_licensingRange≀3.7.002
OR
avevahistorianRange<2020
OR
avevahistorianMatch2020-
OR
avevahistorianMatch2020r2
OR
avevahistorianMatch2020r2_p01
OR
avevaintouchRange<2020
OR
avevaintouchMatch2020-
OR
avevaintouchMatch2020r2
OR
avevaintouchMatch2020r2_p01
OR
avevamanufacturing_execution_systemRange<2020
OR
avevamanufacturing_execution_systemMatch2020
OR
avevamanufacturing_execution_systemMatch2020p01
OR
avevamobile_operatorRange<2020
OR
avevamobile_operatorMatch2020
OR
avevamobile_operatorMatch2020-
OR
avevamobile_operatorMatch2020r1
OR
avevaplant_scadaRange<2020
OR
avevaplant_scadaMatch2020-
OR
avevaplant_scadaMatch2020r2
OR
avevarecipe_managementRange<2020
OR
avevarecipe_managementMatch2020-
OR
avevarecipe_managementMatch2020update_1_patch_2
OR
avevasystem_platformRange<2020
OR
avevasystem_platformMatch2020-
OR
avevasystem_platformMatch2020r2
OR
avevasystem_platformMatch2020r2_p01
OR
avevatelemetry_serverMatch2020r2-
OR
avevatelemetry_serverMatch2020r2sp1
OR
avevawork_tasksRange<2020
OR
avevawork_tasksMatch2020-
OR
avevawork_tasksMatch2020update_1
OR
avevawork_tasksMatch2020update_2

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "SystemPlatform",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 R2 SP1 P01",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Historian",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 R2 SP1 P01",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Application Server",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 R2 SP1 P01",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "InTouch",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 R2 SP1 P01",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Enterprise Licensing (formerly known as License Manager)",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "3.7.002",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Manufacturing Execution System (formerly known as Wonderware MES)",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 P01",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Recipe Management",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 R2 Update 1 Patch 2 ",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Batch Management",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 SP1 ",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Edge (formerly known as Indusoft Web Studio)",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 R2 SP1 P01",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Worktasks (formerly known as Workflow Management)",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 U2",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Plant SCADA (formerly known as Citect)",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 R2 Update 15",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Mobile Operator (formerly known as IntelaTrac Mobile Operator Rounds)",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 R1",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Communication Drivers Pack",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 R2 SP1",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Telemetry Server",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 R2 SP1",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.8 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.2%

Related for CVE-2023-33873