CVE-2023-34982

MEDIUM

AVEVA Batch Management < 2020 - Authenticated Denial of Service via File Deletion

Title source: llm
STIX 2.1

Description

This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.

References (2)

Core 2

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 12.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-610 CWE-73
Status published
Products (23)
aveva/batch_management 2020 (2 CPE variants)
aveva/batch_management < 2020
aveva/communication_drivers 2020 (3 CPE variants)
aveva/communication_drivers < 2020
aveva/edge < 20.1.101
aveva/enterprise_licensing < 3.7.002
aveva/historian 2020 (3 CPE variants)
aveva/historian < 2020
aveva/intouch 2020 (3 CPE variants)
aveva/intouch < 2020
... and 13 more
Published Nov 15, 2023
Tracked Since Feb 18, 2026