CVE-2023-1256: Critical severity aveva plant scada vulnerability
The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-1256?
CVE-2023-1256 is a vulnerability in AVEVA Plant SCADA and AVEVA Telemetry Server that could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.
How severe is CVE-2023-1256?
CVE-2023-1256 has a severity rating of 9.8 out of 10, which is considered critical.
Which versions of AVEVA Plant SCADA are affected by CVE-2023-1256?
CVE-2023-1256 affects AVEVA Plant SCADA versions 2020r2, 2020r2-update_10, 2023, and 2023-update_10.
Which version of AVEVA Telemetry Server is affected by CVE-2023-1256?
CVE-2023-1256 affects AVEVA Telemetry Server versions 2020r2 and 2020r2-sp1.
How can I fix CVE-2023-1256?
To fix CVE-2023-1256, it is recommended to apply the latest security updates and patches provided by AVEVA.