CVE-2023-34982

MEDIUM

Aveva Batch Management < 2020 - Denial of Service

Title source: rule
STIX 2.1

Description

This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.

Scores

CVSS v3 5.5
EPSS 0.0009
EPSS Percentile 25.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-610 CWE-73
Status published
Products (23)
aveva/batch_management 2020 (2 CPE variants)
aveva/batch_management < 2020
aveva/communication_drivers 2020 (3 CPE variants)
aveva/communication_drivers < 2020
aveva/edge < 20.1.101
aveva/enterprise_licensing < 3.7.002
aveva/historian 2020 (3 CPE variants)
aveva/historian < 2020
aveva/intouch 2020 (3 CPE variants)
aveva/intouch < 2020
... and 13 more
Published Nov 15, 2023
Tracked Since Feb 18, 2026