CVE-2024-3468: Deserialization of Untrusted Data in AVEVA PI Web API
There is a vulnerability in AVEVA PI Web API that could allow malicious code to execute on the PI Web API environment under the privileges of an interactive user that was socially engineered to use API XML import functionality with content supplied by an attacker.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3468?
CVE-2024-3468 has a medium severity rating due to the potential for unauthorized code execution.
How do I fix CVE-2024-3468?
To fix CVE-2024-3468, ensure that users are educated on safe API usage and implement access controls to limit the API XML import functionality.
What are the potential impacts of CVE-2024-3468?
The potential impacts of CVE-2024-3468 include unauthorized code execution and possible compromise of the PI Web API environment.
Who is affected by CVE-2024-3468?
Organizations using AVEVA PI Web API are affected by CVE-2024-3468, particularly if interactive users engage with the API XML import functionality.
Is there a way to mitigate the risks associated with CVE-2024-3468?
Yes, mitigating risks from CVE-2024-3468 involves user training, implementing input validation, and strengthening user permissions.