CVE-2024-3467: Deserialization of Untrusted Data in AVEVA PI Asset Framework Client
There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by an attacker.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3467?
CVE-2024-3467 is considered a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2024-3467?
To remediate CVE-2024-3467, users should update AVEVA PI Asset Framework Client to the latest version that includes security patches.
What versions of AVEVA PI Asset Framework Client are affected by CVE-2024-3467?
CVE-2024-3467 affects AVEVA PI Asset Framework Client 2018 SP3 Patch 4 and the 2023 version.
Can CVE-2024-3467 be exploited remotely?
CVE-2024-3467 requires user interaction, making it a social engineering attack that could lead to remote code execution.
What type of vulnerability is CVE-2024-3467?
CVE-2024-3467 is classified as a code execution vulnerability stemming from insecure XML handling.