Aveva Intouch vulnerabilities

4 known vulnerabilities affecting aveva/intouch.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2024-7113HIGHCVSS 8.7≤ 2023 R2 P012024-08-13
CVE-2024-7113 [HIGH] CWE-770 CVE-2024-7113: If exploited, this vulnerability could cause a SuiteLink server to consume excessive system resource If exploited, this vulnerability could cause a SuiteLink server to consume excessive system resources and slow down processing of Data I/O for the duration of the attack.
cvelistv5nvd
CVE-2023-33873HIGHCVSS 7.8fixed in 2020v2020+1 more2023-11-15
CVE-2023-33873 [HIGH] CWE-250 CVE-2023-33873: This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user wi This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine.
cvelistv5nvd
CVE-2023-34982HIGHCVSS 7.1fixed in 2020v2020+1 more2023-11-15
CVE-2023-34982 [HIGH] CWE-73 CVE-2023-34982: This external control vulnerability, if exploited, could allow a local OS-authenticated user with s This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.
cvelistv5nvd
CVE-2021-32942MEDIUMCVSS 5.5≥ unspecified, ≤ 2020 R22021-06-09
CVE-2021-32942 [MEDIUM] CWE-316 CVE-2021-32942: The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prio The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location.
cvelistv5nvd