ICSA-23-073-04: Aveva plant scada vulnerability
Affected Software
2 affected components
AVEVA Plant SCADA 2023, AVEVA Plant SCADA 2020R2 Update 10 and all prior versions
AVEVA Telemetry Server 2020 R2 SP1 and all prior versions
Event History
Feb 21, 2025
Advisory Published
06:10 AM
Frequently Asked Questions
1
What is the severity of ICSA-23-073-04?
The severity of ICSA-23-073-04 is rated as critical due to its potential for remote exploitation.
2
How do I fix ICSA-23-073-04?
To fix ICSA-23-073-04, update AVEVA Plant SCADA to version 2023 or 2020R2 Update 10 and ensure the Telemetry Server is updated to 2020 R2 SP1 or later.
3
What vulnerabilities are addressed in ICSA-23-073-04?
ICSA-23-073-04 addresses multiple vulnerabilities, including potential buffer overflows that could lead to remote code execution.
4
Which versions are affected by ICSA-23-073-04?
ICSA-23-073-04 affects AVEVA Plant SCADA 2023, AVEVA Plant SCADA 2020R2 Update 10, and all prior versions, as well as AVEVA Telemetry Server 2020 R2 SP1 and earlier.
5
Is there a workaround for ICSA-23-073-04 while waiting for a patch?
There are no known workarounds for ICSA-23-073-04; updating the software is recommended as the primary mitigation.