PT-2024-4214 · Aveva · Aveva Pi Asset Framework Client

Published

2024-06-11

·

Updated

2024-10-03

·

CVE-2024-3467

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AVEVA PI Asset Framework Client (affected versions not specified)
Description The issue allows malicious code to execute on the PI System Explorer environment under the privileges of an interactive user. This can happen when an attacker socially engineers a user to import specially crafted XML data. The vulnerability is related to the restoration of untrusted data in memory, which can be exploited to execute arbitrary code using specially crafted data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2024-04700
CVE-2024-3467

Affected Products

Aveva Pi Asset Framework Client