CVE Vulnerabilities

CVE-2023-34348

Improper Check or Handling of Exceptional Conditions

Published: Jan 18, 2024 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to remotely crash the PI Message Subsystem of a PI Server, resulting in a denial-of-service condition.

Weakness

The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.

Affected Software

Name Vendor Start Version End Version
Pi_server Aveva * 2018 (excluding)
Pi_server Aveva 2018 (including) 2018 (including)
Pi_server Aveva 2018-sp3_patch_5 (including) 2018-sp3_patch_5 (including)
Pi_server Aveva 2023 (including) 2023 (including)

References