CVE-2023-34982
MEDIUMAVEVA Batch Management < 2020 - Authenticated Denial of Service via File Deletion
Title source: llmDescription
This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.
References (2)
Core 2
Core References
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-318-01
Scores
CVSS v3
5.5
EPSS
0.0022
EPSS Percentile
12.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-610
CWE-73
Status
published
Products (23)
aveva/batch_management
2020 (2 CPE variants)
aveva/batch_management
< 2020
aveva/communication_drivers
2020 (3 CPE variants)
aveva/communication_drivers
< 2020
aveva/edge
< 20.1.101
aveva/enterprise_licensing
< 3.7.002
aveva/historian
2020 (3 CPE variants)
aveva/historian
< 2020
aveva/intouch
2020 (3 CPE variants)
aveva/intouch
< 2020
... and 13 more
Published
Nov 15, 2023
Tracked Since
Feb 18, 2026