CVE-2023-34982: AVEVA Operations Control Logger External Control of File Name or Path
This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-34982?
CVE-2023-34982 has a high severity rating due to its potential for local authenticated users to delete files with system privileges.
How do I fix CVE-2023-34982?
To remediate CVE-2023-34982, apply the latest security patches provided by Aveva for the affected software versions.
What products are affected by CVE-2023-34982?
CVE-2023-34982 affects various Aveva products including Batch Management, Communication Drivers, Edge, Historian, and System Platform.
Can CVE-2023-34982 lead to a denial of service?
Yes, exploiting CVE-2023-34982 can result in denial of service by allowing unauthorized file deletions.
Who is vulnerable to CVE-2023-34982?
Local OS-authenticated users with standard privileges are vulnerable to the exploitation of CVE-2023-34982.