PT-2024-4214 · Aveva · Aveva Pi Asset Framework Client

CVE-2024-3467

·

Published

2024-06-11

·

Updated

2024-10-03

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AVEVA PI Asset Framework Client (affected versions not specified)
Description The issue allows malicious code to execute on the PI System Explorer environment under the privileges of an interactive user. This can happen when an attacker socially engineers a user to import specially crafted XML data. The vulnerability is related to the restoration of untrusted data in memory, which can be exploited to execute arbitrary code using specially crafted data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04700
CVE-2024-3467

Affected Products

Aveva Pi Asset Framework Client