CVE-2023-33873: Aveva Batch Management
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine.
Affected products
- Aveva Batch Management: before 2020 (fixed in 2020); version 2020 only
- Aveva Communication Drivers: before 2020 (fixed in 2020); version 2020 only
- Aveva Edge: up to and including 20.1.101
- Aveva Enterprise Licensing: up to and including 3.7.002
- Aveva Historian: before 2020 (fixed in 2020); version 2020 only
- Aveva Intouch: before 2020 (fixed in 2020); version 2020 only
- Aveva Manufacturing Execution System: before 2020 (fixed in 2020); version 2020 only
- Aveva Mobile Operator: before 2020 (fixed in 2020); version 2020 only
- Aveva Plant Scada: before 2020 (fixed in 2020); version 2020 only
- Aveva Recipe Management: before 2020 (fixed in 2020); version 2020 only
- Aveva System Platform: before 2020 (fixed in 2020); version 2020 only
- Aveva Telemetry Server: version 2020r2 only
- Aveva Work Tasks: before 2020 (fixed in 2020); version 2020 only
Published 2023-11-15. Last modified 2026-06-17.