CVE-2024-3467

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
12/06/2024
Last modified:
03/10/2024

Description

There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by an attacker.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:aveva:pi_asset_framework_client:2018:sp3_patch_4:*:*:*:*:*:*
cpe:2.3:a:aveva:pi_asset_framework_client:2023:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools