CVE-2023-34348: Improper Check or Handling of Exceptional Conditions in Aveva PI Server
AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to remotely crash the PI Message Subsystem of a PI Server, resulting in a denial-of-service condition.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-34348?
CVE-2023-34348 is considered a high severity vulnerability due to its potential to allow remote denial-of-service attacks.
How do I fix CVE-2023-34348?
To mitigate CVE-2023-34348, it is recommended to upgrade to a patched version of AVEVA PI Server 2023 or 2018 SP3 P06 and above.
What impact does CVE-2023-34348 have on AVEVA PI Server?
CVE-2023-34348 can allow an unauthenticated user to remotely crash the PI Message Subsystem, resulting in a denial-of-service condition.
Which AVEVA PI Server versions are affected by CVE-2023-34348?
CVE-2023-34348 affects AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior.
Can CVE-2023-34348 be exploited remotely?
Yes, CVE-2023-34348 can be exploited remotely by unauthenticated users to cause a service disruption.