There is a vulnerability in AVEVA PI Web API that could allow malicious code to execute on the PI Web API environment under the privileges of an interactive user that was socially engineered to use API XML import functionality with content supplied by an attacker.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: icscert
Published: 2024-06-12T21:04:28.259Z
Updated: 2024-08-01T20:12:07.636Z
Reserved: 2024-04-08T15:55:44.887Z
Link: CVE-2024-3468

Updated: 2024-08-01T20:12:07.636Z

Status : Awaiting Analysis
Published: 2024-06-12T21:15:50.747
Modified: 2024-11-21T09:29:39.907
Link: CVE-2024-3468

No data.