First published: Thu Mar 16 2023(Updated: )
The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Aveva Aveva Plant Scada | =2020r2 | |
Aveva Aveva Plant Scada | =2020r2-update_10 | |
Aveva Aveva Plant Scada | =2023 | |
Aveva Aveva Plant Scada | =2023-update_10 | |
AVEVA Telemetry Server | =2020r2 | |
AVEVA Telemetry Server | =2020r2-sp1 | |
AVEVA Plant SCADA 2023, AVEVA Plant SCADA 2020R2 Update 10 and all prior versions | ||
AVEVA Telemetry Server 2020 R2 SP1 and all prior versions |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1256 is a vulnerability in AVEVA Plant SCADA and AVEVA Telemetry Server that could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.
CVE-2023-1256 has a severity rating of 9.8 out of 10, which is considered critical.
CVE-2023-1256 affects AVEVA Plant SCADA versions 2020r2, 2020r2-update_10, 2023, and 2023-update_10.
CVE-2023-1256 affects AVEVA Telemetry Server versions 2020r2 and 2020r2-sp1.
To fix CVE-2023-1256, it is recommended to apply the latest security updates and patches provided by AVEVA.