Skip to main content

Vendor archive

aveva CVEs

Beta · best-effort

68 CVEs tagged to vendor aveva18 Critical, 35 High, 12 Medium, 3 Low, 0 Unrated.

CVE-2025-65118

Published Jan 16, 2026

The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimization services into loading arbitrary code and escalate privil…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-65117

Published Jan 16, 2026

The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed OLE objects into graphics, and escalate their privileges to…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64769

Published Jan 16, 2026

The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted and could become subject to hijacking or data leakage in cer…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64729

Published Jan 16, 2026

The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed code, and escalate their priv…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64691

Published Jan 16, 2026

The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scripts and escalate privileges to OS system, potentially res…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-61943

Published Jan 16, 2026

The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code executi…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-61937

Published Jan 16, 2026

The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of “taoimr” service, potentially resulting…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-3467

Published Jun 12, 2024

There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34348

Published Jan 18, 2024

AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to remotely crash the PI Message Subsystem of a PI Server…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31274

Published Jan 18, 2024

AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to cause the PI Message Subsystem of a PI Server to consu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-42797

Published Dec 16, 2023

Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user acc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-42796

Published Dec 16, 2023

An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticated arbitrary commands to be executed.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-42794

Published Dec 16, 2023

An issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a client to provide a malicious connection string that could…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34982

Published Nov 15, 2023

This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where th…

CVSS 5.5 · Medium

CVE-2023-33873

Published Nov 15, 2023

This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where thes…

CVSS 7.8 · High

CVE-2022-36970

Published Mar 29, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 20.0 Build: 4201.2111.1802.0000 Service Pack 2. User interaction is re…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36969

Published Mar 29, 2023

This vulnerability allows remote attackers to disclose sensitive information on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is req…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28688

Published Mar 29, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28687

Published Mar 29, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28686

Published Mar 29, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28685

Published Mar 29, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1256

Published Mar 16, 2023

The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-23854

Published Dec 23, 2022

AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on t…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 68 CVEsPage 1 of 3