The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-073-04 Third Party Advisory US Government Resource
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: icscert

Published: 2023-03-16T18:33:52.907Z

Updated: 2023-03-16T18:33:52.907Z

Reserved: 2023-03-07T16:15:30.636Z


Link: CVE-2023-1256

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-03-16T19:15:18.227

Modified: 2023-11-07T04:02:56.390


Link: CVE-2023-1256

JSON object: View

cve-icon Redhat Information

No data.

CWE

No CWE.