CVE-2023-1256

The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-073-04 Third Party Advisory US Government Resource
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:aveva:telemetry_server:2020r2:-:*:*:*:*:*:*
cpe:2.3:a:aveva:telemetry_server:2020r2:sp1:*:*:*:*:*:*
cpe:2.3:a:aveva:aveva_plant_scada:2020r2:-:*:*:*:*:*:*
cpe:2.3:a:aveva:aveva_plant_scada:2020r2:update_10:*:*:*:*:*:*
cpe:2.3:a:aveva:aveva_plant_scada:2023:-:*:*:*:*:*:*
cpe:2.3:a:aveva:aveva_plant_scada:2023:update_10:*:*:*:*:*:*

Information

Published : 2023-03-16 12:15

Updated : 2023-03-22 13:56


NVD link : CVE-2023-1256

Mitre link : CVE-2023-1256


JSON object : View

CWE
CWE-285

Improper Authorization

Advertisement

dedicated server usa

Products Affected

aveva

  • aveva_plant_scada
  • telemetry_server