Security Advisory

CVE-2024-3468

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-06-12 21:04:28
Last updated 2024-08-01 20:12:07
Assigner icscert
State PUBLISHED

Description

There is a vulnerability in AVEVA PI Web API that could allow malicious code to execute on the PI Web API environment under the privileges of an interactive user that was socially engineered to use API XML import functionality with content supplied by an attacker.