High severity7.8NVD Advisory· Published Jun 12, 2024· Updated Jun 17, 2026
CVE-2024-3467
CVE-2024-3467
Description
There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by an attacker.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4(expand)+ 3 more
- (no CPE)
- cpe:2.3:a:aveva:pi_asset_framework_client:2018:sp3_patch_4:*:*:*:*:*:*
- cpe:2.3:a:aveva:pi_asset_framework_client:2023:*:*:*:*:*:*:*
- (no CPE)range: 2023
Patches
Vulnerability mechanics
References
1- www.cisa.gov/news-events/ics-advisories/icsa-24-163-03nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.