← Vulnerability feed

Vulnerability record · CVE-2023-34982 · published 15 November 2023

CVE-2023-34982: Aveva batch management vulnerability

Aveva · Batch Management

This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.

7.1 CVSS 3.1 High EPSS 0.22% · top 88.9% CWE-73 · CWE-73CWE-610 · CWE-610
7.1CVSS 3.1 base score
0.22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
13Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Affected products

13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-34982 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-42796Aveva edge os command injection vulnerabilityAn issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticated arbitra…EPSS 1.1%9.8CVE-2018-17914Aveva indusoft web studio vulnerabilityInduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability…EPSS 4.6%9.8CVE-2018-17916Aveva indusoft web studio stack-based buffer overflow vulnerabilityInduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker …EPSS 3.7%7.8CVE-2023-33873Aveva batch management execution with unnecessary privileges vulnerabilityThis privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privi…EPSS 0.24%7.8CVE-2021-38410Aveva batch management uncontrolled search path element vulnerabilityAVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled …EPSS 0.22%7.5CVE-2021-42797Aveva edge path traversal vulnerabilityPath traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Window…EPSS 1.0%5.3CVE-2021-42794Aveva edge vulnerabilityAn issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a client to provide a malicious…EPSS 1.2%8.8CVE-2025-33053Microsoft Windows WebDAV Internet Shortcut File Path Control RCEWindows Internet Shortcut (.url) files allow external control of a file name or path, which an unauthorized attacker can abuse to execute code over a…KEVEPSS 87%analysed

Source: NIST National Vulnerability Database (record CVE-2023-34982), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.