Vulnerability Description
The vulnerability, if exploited, could allow a malicious entity with access to the file system to achieve arbitrary code execution and privilege escalation by tricking AVEVA Edge to load an unsafe DLL.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aveva | Platform Common Services | 4.4.6 |
| Aveva | Batch Management | 2020 |
| Aveva | Enterprise Data Management | 2021 |
| Aveva | Manufacturing Execution System | 2020 |
| Aveva | Mobile Operator | 2020 |
| Aveva | System Platform | 2020 |
| Aveva | Work Tasks | 2020 |
Related Weaknesses (CWE)
References
- https://www.aveva.com/en/support-and-success/cyber-security-updates/Vendor Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-032-03Third Party AdvisoryUS Government Resource
- https://www.aveva.com/en/support-and-success/cyber-security-updates/Vendor Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-032-03Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2023-6132?
CVE-2023-6132 is a vulnerability with a CVSS score of 7.3 (HIGH). The vulnerability, if exploited, could allow a malicious entity with access to the file system to achieve arbitrary code execution and privilege escalation by tricking AVEVA Edge to load an unsafe DL...
How severe is CVE-2023-6132?
CVE-2023-6132 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-6132?
Check the references section above for vendor advisories and patch information. Affected products include: Aveva Platform Common Services, Aveva Batch Management, Aveva Enterprise Data Management, Aveva Manufacturing Execution System, Aveva Mobile Operator.