CVE-2023-33873: Aveva Batch Management

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine.

Affected products

  • Aveva Batch Management: before 2020 (fixed in 2020); version 2020 only
  • Aveva Communication Drivers: before 2020 (fixed in 2020); version 2020 only
  • Aveva Edge: up to and including 20.1.101
  • Aveva Enterprise Licensing: up to and including 3.7.002
  • Aveva Historian: before 2020 (fixed in 2020); version 2020 only
  • Aveva Intouch: before 2020 (fixed in 2020); version 2020 only
  • Aveva Manufacturing Execution System: before 2020 (fixed in 2020); version 2020 only
  • Aveva Mobile Operator: before 2020 (fixed in 2020); version 2020 only
  • Aveva Plant Scada: before 2020 (fixed in 2020); version 2020 only
  • Aveva Recipe Management: before 2020 (fixed in 2020); version 2020 only
  • Aveva System Platform: before 2020 (fixed in 2020); version 2020 only
  • Aveva Telemetry Server: version 2020r2 only
  • Aveva Work Tasks: before 2020 (fixed in 2020); version 2020 only

Published 2023-11-15. Last modified 2026-06-17.