CVE-2023-1256: Aveva Plant Scada

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.

Affected products

  • Aveva Aveva Plant Scada: version 2020r2 only; version 2023 only
  • Aveva Telemetry Server: version 2020r2 only

Published 2023-03-16. Last modified 2026-06-17.