AVEVA Operations Control Logger privilege escalation | CVE-2023-33873

NAME
__________
AVEVA Operations Control Logger privilege escalation

Platforms Affected:
AVEVA AVEVA SystemPlatform 2020 R2 SP1 P01
AVEVA AVEVA Historian 2020 R2 SP1 P01
AVEVA AVEVA Application Server 2020 R2 SP1 P01
AVEVA AVEVA InTouch 2020 R2 SP1 P01
AVEVA AVEVA Enterprise Licensing (formerly known as License Manager) 3.7.002
AVEVA AVEVA Manufacturing Execution System 2020 P01
AVEVA AVEVA Recipe Management 2020 R2 Update 1 Patch 2
AVEVA AVEVA Batch Management 2020 SP1
AVEVA AVEVA Edge 2020 R2 SP1 P01
AVEVA AVEVA Worktasks 2020 U2
AVEVA AVEVA Plant SCADA 2020 R2 Update 15
AVEVA AVEVA Mobile Operator 2020 R1
AVEVA AVEVA Telemetry Server 2020 R2 SP1

Risk Level:
7.8

Exploitability:
Unproven

Consequences:
Gain Privileges

DESCRIPTION
__________

AVEVA Operations Control Logger could allow a local authenticated attacker to gain elevated privileges on the system, caused by the execution with unnecessary privileges flaw. By sending a specially crafted request, an attacker could exploit this vulnerability to escalate to system privilege.

CVSS 3.0 Information
__________

Privileges Required:
Low

User Interaction:
None

Scope:
Unchanged

Access Vector:
Local



A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

 To keep up to date follow us on the below channels.