CVE-2024-3467
HIGHAVEVA PI Asset Framework Client - Remote Code Execution via Malicious XML Import
Title source: llmDescription
There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by an attacker.
References (1)
Core 1
Core References
Third Party Advisory, US Government Resource government-resource
https://www.cisa.gov/news-events/ics-advisories/icsa-24-163-03
Scores
CVSS v3
7.8
EPSS
0.0019
EPSS Percentile
8.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-502
Status
published
Products (2)
aveva/pi_asset_framework_client
2018 sp3_patch_4
aveva/pi_asset_framework_client
2023
Published
Jun 12, 2024
Tracked Since
Feb 18, 2026