VYPR
Critical severity9.8NVD Advisory· Published Mar 16, 2023· Updated Jun 17, 2026

CVE-2023-1256

CVE-2023-1256

Description

The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

10
  • cpe:2.3:a:aveva:aveva_plant_scada:2020r2:-:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:aveva:aveva_plant_scada:2020r2:-:*:*:*:*:*:*
    • cpe:2.3:a:aveva:aveva_plant_scada:2020r2:update_10:*:*:*:*:*:*
    • cpe:2.3:a:aveva:aveva_plant_scada:2023:-:*:*:*:*:*:*
    • cpe:2.3:a:aveva:aveva_plant_scada:2023:update_10:*:*:*:*:*:*
  • cpe:2.3:a:aveva:telemetry_server:2020r2:-:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:aveva:telemetry_server:2020r2:-:*:*:*:*:*:*
    • cpe:2.3:a:aveva:telemetry_server:2020r2:sp1:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 2020 R2 SP1
  • Aveva/Plant Scadallm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 2020R2 Update 10

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.