Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g5fx-mv2q-2jpr

Опубликовано: 12 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 7
CVSS3: 7.8

Описание

There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by an attacker.

There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by an attacker.

EPSS

Процентиль: 35%
0.00139
Низкий

7 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 7.8
nvd
больше 1 года назад

There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by an attacker.

CVSS3: 7.3
fstec
больше 1 года назад

Уязвимость приложения для управления данными о производственных процессах AVEVA PI Asset Framework (AF) Client, связанная с восстановлением в памяти недостоверных данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 35%
0.00139
Низкий

7 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-502