There is a vulnerability in AVEVA PI Web API that could allow malicious code to execute on the PI Web API environment under the privileges of an interactive user that was socially engineered to use API XML import functionality with content supplied by an attacker.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2024-06-12T21:04:28.259Z
Updated: 2024-08-01T20:12:07.636Z
Reserved: 2024-04-08T15:55:44.887Z
Link: CVE-2024-3468
Vulnrichment
Updated: 2024-08-01T20:12:07.636Z
NVD
Status : Awaiting Analysis
Published: 2024-06-12T21:15:50.747
Modified: 2024-06-13T18:36:09.010
Link: CVE-2024-3468
Redhat
No data.