CVE-2023-6132

HIGH

AVEVA Edge - RCE

Title source: llm

Description

The vulnerability, if exploited, could allow a malicious entity with access to the file system to achieve arbitrary code execution and privilege escalation by tricking AVEVA Edge to load an unsafe DLL.

Scores

CVSS v3 7.3
EPSS 0.0004
EPSS Percentile 11.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (4)

aveva/platform_common_services
aveva/platform_common_services
aveva/platform_common_services
aveva/platform_common_services

Timeline

Published Feb 29, 2024
Tracked Since Feb 18, 2026