Execution with unnecessary privileges in AVEVA Software, LLC. products - CVE-2023-33873

 

Execution with unnecessary privileges in AVEVA Software, LLC. products - CVE-2023-33873

Published: November 15, 2023


Vulnerability identifier: #VU83208
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-33873
CWE-ID: CWE-250
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to application binary has a setuid bit. A local low-privileged user can run the affected binary and execute arbitrary code on the system with root privileges.


Affected software

AVEVA SystemPlatform
AVEVA Telemetry Server
AVEVA Application Server
AVEVA Plant SCADA
AVEVA Enterprise Licensing
AVEVA Worktasks
AVEVA Recipe Management
AVEVA Operations Control Logger
AVEVA Historian
AVEVA Communication Drivers Pack
AVEVA InTouch
AVEVA Manufacturing Execution System
AVEVA Mobile Operator
AVEVA Batch Management
AVEVA Edge

How to mitigate CVE-2023-33873

Install updates from vendor's website.

AVEVA SystemPlatform - update to 2023
AVEVA Historian - update to 2023
AVEVA Telemetry Server - update to 2020 R2 SP2
AVEVA Application Server - update to 2023
AVEVA Communication Drivers Pack - update to 2023.1
AVEVA InTouch - update to 2023
AVEVA Plant SCADA - update to 2023
AVEVA Enterprise Licensing - update to 4.0
AVEVA Manufacturing Execution System - update to 2023
AVEVA Worktasks - update to 2023 SP1
AVEVA Recipe Management - update to 2023
AVEVA Mobile Operator - update to 2020 R2
AVEVA Batch Management - update to 2023
AVEVA Edge - addressed in versions 2020 R2 SP2, 2023
AVEVA Operations Control Logger - update to 22.1

External References

Related Security Bulletins