AVEVA Operations Control Logger

View CSAF

1. EXECUTIVE SUMMARY

  • CVSS v3 7.8
  • ATTENTION: Low attack complexity
  • Vendor: AVEVA
  • Equipment: Operations Control Logger
  • Vulnerabilities: Execution with Unnecessary Privileges, External Control of File Name or Path

2. RISK EVALUATION

Successful exploitation of these vulnerabilities could allow privilege escalation or denial of service.

3. TECHNICAL DETAILS

3.1 AFFECTED PRODUCTS

AVEVA has created a security update to address vulnerabilities in the AVEVA Operations Control Logger (formerly known as ArchestrA Logger), impacting the following products:

  • AVEVA SystemPlatform: 2020 R2 SP1 P01 and prior
  • AVEVA Historian: 2020 R2 SP1 P01 and prior
  • AVEVA Application Server: 2020 R2 SP1 P01 and prior
  • AVEVA InTouch: 2020 R2 SP1 P01 and prior
  • AVEVA Enterprise Licensing (formerly known as License Manager): version 3.7.002 and prior
  • AVEVA Manufacturing Execution System (formerly known as Wonderware MES): 2020 P01 and prior
  • AVEVA Recipe Management: 2020 R2 Update 1 Patch 2 and prior
  • AVEVA Batch Management: 2020 SP1 and prior
  • AVEVA Edge (formerly known as Indusoft Web Studio): 2020 R2 SP1 P01 and prior
  • AVEVA Worktasks (formerly known as Workflow Management): 2020 U2 and prior
  • AVEVA Plant SCADA (formerly known as Citect): 2020 R2 Update 15 and prior
  • AVEVA Mobile Operator (formerly known as IntelaTrac Mobile Operator Rounds): 2020 R1 and prior
  • AVEVA Communication Drivers Pack: 2020 R2 SP1 and prior
  • AVEVA Telemetry Server: 2020 R2 SP1 and prior

3.2 Vulnerability Overview

3.2.1 Execution with Unnecessary Privileges CWE-250

This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine.

This article has been indexed from All CISA Advisories

Read the original article:

AVEVA Operations Control Logger