← Vulnerability feed

Vulnerability record · CVE-2023-33873 · published 15 November 2023

CVE-2023-33873: Aveva batch management execution with unnecessary privileges vulnerability

Aveva · Batch Management

This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine.

7.8 CVSS 3.1 High EPSS 0.24% · top 86.9% CWE-250 · Execution with unnecessary privileges
7.8CVSS 3.1 base score
0.24%EPSS exploitation probability, 30 days
NoNot in CISA KEV
13Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-33873 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-42796Aveva edge os command injection vulnerabilityAn issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticated arbitra…EPSS 1.1%9.8CVE-2018-17914Aveva indusoft web studio vulnerabilityInduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability…EPSS 4.6%9.8CVE-2018-17916Aveva indusoft web studio stack-based buffer overflow vulnerabilityInduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker …EPSS 3.7%7.8CVE-2021-38410Aveva batch management uncontrolled search path element vulnerabilityAVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled …EPSS 0.22%7.5CVE-2021-42797Aveva edge path traversal vulnerabilityPath traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Window…EPSS 1.0%7.1CVE-2023-34982Aveva batch management vulnerabilityThis external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System pri…EPSS 0.22%5.3CVE-2021-42794Aveva edge vulnerabilityAn issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a client to provide a malicious…EPSS 1.2%6.6CVE-2025-40602SonicWall SMA1000 management console missing authorization privilege escalationThe SonicWall SMA1000 appliance management console (AMC) contains a local privilege escalation flaw caused by insufficient authorization, mapped to C…KEVEPSS 2.8%analysed

Source: NIST National Vulnerability Database (record CVE-2023-33873), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.