There is a vulnerability in AVEVA PI Web API that could allow malicious code to execute on the PI Web API environment under the privileges of an interactive user that was socially engineered to use API XML import functionality with content supplied by an attacker.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2024-06-12T21:04:28.259Z

Updated: 2024-08-01T20:12:07.636Z

Reserved: 2024-04-08T15:55:44.887Z

Link: CVE-2024-3468

cve-icon Vulnrichment

Updated: 2024-08-01T20:12:07.636Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-12T21:15:50.747

Modified: 2024-06-13T18:36:09.010

Link: CVE-2024-3468

cve-icon Redhat

No data.