Lucene search

K
cvelistIcscertCVELIST:CVE-2023-34982
HistoryNov 15, 2023 - 4:28 p.m.

CVE-2023-34982 AVEVA Operations Control Logger External Control of File Name or Path

2023-11-1516:28:35
CWE-73
icscert
www.cve.org
cve-2023-34982
external control
file deletion
denial of service
os-authenticated user

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

7.1 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.3%

This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "SystemPlatform",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 R2 SP1 P01",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Historian",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 R2 SP1 P01",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Application Server",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 R2 SP1 P01",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "InTouch",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 R2 SP1 P01",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Enterprise Licensing (formerly known as License Manager)",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "3.7.002",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Manufacturing Execution System (formerly known as Wonderware MES)",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 P01",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Recipe Management",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 R2 Update 1 Patch 2 ",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Batch Management",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 SP1 ",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Edge (formerly known as Indusoft Web Studio)",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 R2 SP1 P01",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Worktasks (formerly known as Workflow Management)",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 U2",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Plant SCADA (formerly known as Citect)",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 R2 Update 15",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Mobile Operator (formerly known as IntelaTrac Mobile Operator Rounds)",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 R1",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Communication Drivers Pack",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 R2 SP1",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Telemetry Server",
    "vendor": "AVEVA ",
    "versions": [
      {
        "lessThanOrEqual": "2020 R2 SP1",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

7.1 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.3%

Related for CVELIST:CVE-2023-34982