Critical severity9.8NVD Advisory· Published Mar 16, 2023· Updated Jun 17, 2026
CVE-2023-1256
CVE-2023-1256
Description
The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:2.3:a:aveva:aveva_plant_scada:2020r2:-:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:aveva:aveva_plant_scada:2020r2:-:*:*:*:*:*:*
- cpe:2.3:a:aveva:aveva_plant_scada:2020r2:update_10:*:*:*:*:*:*
- cpe:2.3:a:aveva:aveva_plant_scada:2023:-:*:*:*:*:*:*
- cpe:2.3:a:aveva:aveva_plant_scada:2023:update_10:*:*:*:*:*:*
cpe:2.3:a:aveva:telemetry_server:2020r2:-:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:aveva:telemetry_server:2020r2:-:*:*:*:*:*:*
- cpe:2.3:a:aveva:telemetry_server:2020r2:sp1:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 2020 R2 SP1
(expand)+ 1 more
- (no CPE)
- (no CPE)range: 2020R2 Update 10
Patches
Vulnerability mechanics
References
1- www.cisa.gov/news-events/ics-advisories/icsa-23-073-04nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.