Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2023-33873 Details
Description
This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 21, 2024Exploitation: NoneAutomatable: NoTechnical Impact: Total
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.aveva.com/en/support-and-success/cyber-security-updates/ | CVE | Vendor Advisory |
| https://www.cisa.gov/news-events/ics-advisories/icsa-23-318-01 | CVE | Third Party AdvisoryUS Government Resource |
| https://www.aveva.com/en/support-and-success/cyber-security-updates/ | [email protected] | Vendor Advisory |
| https://www.cisa.gov/news-events/ics-advisories/icsa-23-318-01 | [email protected] | Third Party AdvisoryUS Government Resource |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
| CWE-250 | Execution with Unnecessary Privileges | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| aveva batch management | < 2020 2020 - 2020 sp1 |
CPE
Remediation
| |
| aveva communication drivers | < 2020 2020 - 2020 r2 2020 r2_p01 |
CPE
Remediation
| |
| aveva edge | <= 20.1.101 |
CPE
Remediation
| |
| aveva enterprise licensing | <= 3.7.002 |
CPE
Remediation
| |
| aveva historian | < 2020 2020 - 2020 r2 2020 r2_p01 |
CPE
Remediation
| |
| aveva intouch | < 2020 2020 - 2020 r2 2020 r2_p01 |
CPE
Remediation
| |
| aveva manufacturing execution system | < 2020 2020 2020 p01 |
CPE
Remediation
| |
| aveva mobile operator | < 2020 2020 2020 - 2020 r1 |
CPE
Remediation
| |
| aveva plant scada | < 2020 2020 - 2020 r2 |
CPE
Remediation
| |
| aveva recipe management | < 2020 2020 - 2020 update_1_patch_2 |
CPE
Remediation
| |
| aveva system platform | < 2020 2020 - 2020 r2 2020 r2_p01 |
CPE
Remediation
| |
| aveva telemetry server | 2020r2 - 2020r2 sp1 |
CPE
Remediation
| |
| aveva work tasks | < 2020 2020 - 2020 update_1 2020 update_2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 8, 2023 | Initial Analysis | [email protected] |
| Nov 15, 2023 | New CVE Received | [email protected] |