Description
This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.
Scores
CVSS v3
5.5
EPSS
0.0009
EPSS Percentile
25.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-610
CWE-73
Status
published
Products (23)
aveva/batch_management
2020 (2 CPE variants)
aveva/batch_management
< 2020
aveva/communication_drivers
2020 (3 CPE variants)
aveva/communication_drivers
< 2020
aveva/edge
< 20.1.101
aveva/enterprise_licensing
< 3.7.002
aveva/historian
2020 (3 CPE variants)
aveva/historian
< 2020
aveva/intouch
2020 (3 CPE variants)
aveva/intouch
< 2020
... and 13 more
Published
Nov 15, 2023
Tracked Since
Feb 18, 2026