This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine.
Conclusion & alert: CVE-2023-33873 is rated Low Risk (36.2/100): CVSS High severity, with low exploitation likelihood (EPSS 0.06%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-03-19 | 0.04% | 0.06% | +0.01% |
| 2 | 2023-11-16 | — | 0.04% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | [email protected] |
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| aveva | batch_management | < 2020 | cpe:2.3:a:aveva:batch_management:*:*:*:*:*:*:*:* |
| aveva | batch_management | 2020 | cpe:2.3:a:aveva:batch_management:2020:-:*:*:*:*:*:* |
| aveva | batch_management | 2020 | cpe:2.3:a:aveva:batch_management:2020:sp1:*:*:*:*:*:* |
| aveva | communication_drivers | < 2020 | cpe:2.3:a:aveva:communication_drivers:*:*:*:*:*:*:*:* |
| aveva | communication_drivers | 2020 | cpe:2.3:a:aveva:communication_drivers:2020:-:*:*:*:*:*:* |
| aveva | communication_drivers | 2020 | cpe:2.3:a:aveva:communication_drivers:2020:r2:*:*:*:*:*:* |
| aveva | communication_drivers | 2020 | cpe:2.3:a:aveva:communication_drivers:2020:r2_p01:*:*:*:*:*:* |
| aveva | edge | <= 20.1.101 | cpe:2.3:a:aveva:edge:*:*:*:*:*:*:*:* |
| aveva | enterprise_licensing | <= 3.7.002 | cpe:2.3:a:aveva:enterprise_licensing:*:*:*:*:*:*:*:* |
| aveva | historian | < 2020 | cpe:2.3:a:aveva:historian:*:*:*:*:*:*:*:* |
| aveva | historian | 2020 | cpe:2.3:a:aveva:historian:2020:-:*:*:*:*:*:* |
| aveva | historian | 2020 | cpe:2.3:a:aveva:historian:2020:r2:*:*:*:*:*:* |
| aveva | historian | 2020 | cpe:2.3:a:aveva:historian:2020:r2_p01:*:*:*:*:*:* |
| aveva | intouch | < 2020 | cpe:2.3:a:aveva:intouch:*:*:*:*:*:*:*:* |
| aveva | intouch | 2020 | cpe:2.3:a:aveva:intouch:2020:-:*:*:*:*:*:* |
| aveva | intouch | 2020 | cpe:2.3:a:aveva:intouch:2020:r2:*:*:*:*:*:* |
| aveva | intouch | 2020 | cpe:2.3:a:aveva:intouch:2020:r2_p01:*:*:*:*:*:* |
| aveva | manufacturing_execution_system | < 2020 | cpe:2.3:a:aveva:manufacturing_execution_system:*:*:*:*:*:*:*:* |
| aveva | manufacturing_execution_system | 2020 | cpe:2.3:a:aveva:manufacturing_execution_system:2020:*:*:*:*:*:*:* |
| aveva | manufacturing_execution_system | 2020 | cpe:2.3:a:aveva:manufacturing_execution_system:2020:p01:*:*:*:*:*:* |
| aveva | mobile_operator | < 2020 | cpe:2.3:a:aveva:mobile_operator:*:*:*:*:*:*:*:* |
| aveva | mobile_operator | 2020 | cpe:2.3:a:aveva:mobile_operator:2020:*:*:*:*:*:*:* |
| aveva | mobile_operator | 2020 | cpe:2.3:a:aveva:mobile_operator:2020:-:*:*:*:*:*:* |
| aveva | mobile_operator | 2020 | cpe:2.3:a:aveva:mobile_operator:2020:r1:*:*:*:*:*:* |
| aveva | plant_scada | < 2020 | cpe:2.3:a:aveva:plant_scada:*:*:*:*:*:*:*:* |
| aveva | plant_scada | 2020 | cpe:2.3:a:aveva:plant_scada:2020:-:*:*:*:*:*:* |
| aveva | plant_scada | 2020 | cpe:2.3:a:aveva:plant_scada:2020:r2:*:*:*:*:*:* |
| aveva | recipe_management | < 2020 | cpe:2.3:a:aveva:recipe_management:*:*:*:*:*:*:*:* |
| aveva | recipe_management | 2020 | cpe:2.3:a:aveva:recipe_management:2020:-:*:*:*:*:*:* |
| aveva | recipe_management | 2020 | cpe:2.3:a:aveva:recipe_management:2020:update_1_patch_2:*:*:*:*:*:* |
| aveva | system_platform | < 2020 | cpe:2.3:a:aveva:system_platform:*:*:*:*:*:*:*:* |
| aveva | system_platform | 2020 | cpe:2.3:a:aveva:system_platform:2020:-:*:*:*:*:*:* |
| aveva | system_platform | 2020 | cpe:2.3:a:aveva:system_platform:2020:r2:*:*:*:*:*:* |
| aveva | system_platform | 2020 | cpe:2.3:a:aveva:system_platform:2020:r2_p01:*:*:*:*:*:* |
| aveva | telemetry_server | 2020r2 | cpe:2.3:a:aveva:telemetry_server:2020r2:-:*:*:*:*:*:* |
| aveva | telemetry_server | 2020r2 | cpe:2.3:a:aveva:telemetry_server:2020r2:sp1:*:*:*:*:*:* |
| aveva | work_tasks | < 2020 | cpe:2.3:a:aveva:work_tasks:*:*:*:*:*:*:*:* |
| aveva | work_tasks | 2020 | cpe:2.3:a:aveva:work_tasks:2020:-:*:*:*:*:*:* |
| aveva | work_tasks | 2020 | cpe:2.3:a:aveva:work_tasks:2020:update_1:*:*:*:*:*:* |
| aveva | work_tasks | 2020 | cpe:2.3:a:aveva:work_tasks:2020:update_2:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.aveva.com/en/support-and-success/cyber-security-updates/ | Vendor Advisory |
| https://www.cisa.gov/news-events/ics-advisories/icsa-23-318-01 | Third Party Advisory US Government Resource |