ICSA-23-318-01: Aveva system platform vulnerability
Affected Software
14 affected components
: AVEVA AVEVA SystemPlatform: 2020 R2 SP1 P01 and prior
: AVEVA AVEVA Historian: 2020 R2 SP1 P01 and prior
: AVEVA AVEVA Application Server: 2020 R2 SP1 P01 and prior
: AVEVA AVEVA InTouch: 2020 R2 SP1 P01 and prior
: AVEVA AVEVA Enterprise Licensing (formerly known as License Manager): version 3.7.002 and prior
: AVEVA AVEVA Manufacturing Execution System (formerly known as Wonderware MES): 2020 P01 and prior
: AVEVA AVEVA Recipe Management: 2020 R2 Update 1 Patch 2 and prior
: AVEVA AVEVA Batch Management: 2020 SP1 and prior
: AVEVA AVEVA Edge (formerly known as Indusoft Web Studio): 2020 R2 SP1 P01 and prior
: AVEVA AVEVA Worktasks (formerly known as Workflow Management): 2020 U2 and prior
: AVEVA AVEVA Plant SCADA (formerly known as Citect): 2020 R2 Update 15 and prior
: AVEVA AVEVA Mobile Operator (formerly known as IntelaTrac Mobile Operator Rounds): 2020 R1 and prior
: AVEVA AVEVA Communication Drivers Pack: 2020 R2 SP1 and prior
: AVEVA AVEVA Telemetry Server: 2020 R2 SP1 and prior
Event History
Feb 21, 2025
Advisory Published
01:59 PM
Frequently Asked Questions
1
What is the severity of ICSA-23-318-01?
ICSA-23-318-01 has been rated as a critical vulnerability.
2
How do I fix ICSA-23-318-01?
To fix ICSA-23-318-01, update to the latest version of affected AVEVA products as recommended by the vendor.
3
What products are affected by ICSA-23-318-01?
ICSA-23-318-01 affects several AVEVA products including System Platform, Historian, Application Server, InTouch, Enterprise Licensing, Manufacturing Execution System, Recipe Management, and Batch Management.
4
What kind of vulnerabilities does ICSA-23-318-01 address?
ICSA-23-318-01 addresses multiple vulnerabilities that could allow for unauthorized access or control of the affected AVEVA systems.
5
Is there a workaround for ICSA-23-318-01?
There are no official workarounds suggested for ICSA-23-318-01; the recommended action is to apply updates.