CVE-2023-34982

MEDIUM

Aveva Batch Management < 2020 - Denial of Service

Title source: rule

Description

This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.

Scores

CVSS v3 5.5
EPSS 0.0009
EPSS Percentile 25.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-610 CWE-73
Status published

Affected Products (40)

aveva/batch_management < 2020
aveva/batch_management
aveva/batch_management
aveva/communication_drivers < 2020
aveva/communication_drivers
aveva/communication_drivers
aveva/communication_drivers
aveva/edge < 20.1.101
aveva/enterprise_licensing < 3.7.002
aveva/historian < 2020
aveva/historian
aveva/historian
aveva/historian
aveva/intouch < 2020
aveva/intouch
... and 25 more

Timeline

Published Nov 15, 2023
Tracked Since Feb 18, 2026