PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-3467 AVEVA CVE debrief

CVE-2024-3467 is a high-severity vulnerability in AVEVA PI Asset Framework Client that enables arbitrary code execution when an attacker socially engineers an interactive user into importing malicious XML. Published on June 11, 2024, this vulnerability carries a CVSS 3.1 score of 7.3 and requires local access with low attack complexity. The attack vector depends on user interaction—specifically, convincing a user to import untrusted XML into PI System Explorer. Once executed, malicious code runs with the privileges of the compromised interactive user, potentially leading to complete confidentiality, integrity, and availability compromise of the local environment. The vulnerability affects PI Asset Framework Client 2023 and versions through 2018 SP3 P04. AVEVA has released patches addressing this issue, with the recommended fix being an upgrade to PI AF Client 2023 Patch 1 or later. An alternative path exists for legacy deployments via 2018 SP3 Patch 5. Defensive measures include running PI System Explorer with least-privilege accounts and establishing verification procedures for XML import sources.

Vendor
AVEVA
Product
PI Asset Framework Client
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2024-06-11
Original CVE updated
2024-06-11
Advisory published
2024-06-11
Advisory updated
2024-06-11

Who should care

Organizations operating AVEVA PI System infrastructure in industrial environments, particularly those with: (1) engineering workstations running PI System Explorer, (2) operational technology (OT) environments where PI Asset Framework is deployed for process data management, (3) users with administrative or elevated privileges on PI client systems, and (4) environments where external XML configurations or templates are routinely imported. Critical infrastructure operators in energy, manufacturing, and water/wastewater sectors using AVEVA PI systems should prioritize assessment due to potential operational technology impact.

Technical summary

The vulnerability exists in the XML import functionality of PI System Explorer, the client component of AVEVA PI Asset Framework. When a user imports attacker-supplied XML, embedded malicious code executes within the PI System Explorer environment. The attack requires: (1) local access to a system with PI Asset Framework Client installed, (2) an interactive user session with privileges to operate PI System Explorer, and (3) successful social engineering to induce XML import. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H) reflects local attack vector, low complexity, required user interaction, and high impact across confidentiality, integrity, and availability dimensions. No network exploitation path exists; attack surface is limited to authenticated local users with social engineering susceptibility.

Defensive priority

high

Recommended defensive actions

  • Upgrade to PI AF Client 2023 Patch 1 or later as the primary remediation path
  • For legacy environments, deploy PI AF Client 2018 SP3 Patch 5 or later
  • Configure PI System Explorer to run under least-privilege interactive accounts
  • Implement procedural controls to verify XML source trustworthiness before import
  • Review and apply AVEVA security advisory AVEVA-2024-004 for additional guidance
  • Monitor CISA ICS advisories for related industrial control system security updates

Evidence notes

Vulnerability details sourced from CISA ICS Advisory ICSA-24-163-03 published June 11, 2024. CVSS vector AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H confirmed via official advisory. Affected product versions and remediation guidance extracted from CSAF remediation entries.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-3467 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-3467

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-3467 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-3467

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-163-03.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-163-03

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.