The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator Developer (Administrator) roles, resulting in privilege escalation with potential for modification of simulation parameters, training configuration, and training records.
Metrics
Affected Vendors & Products
References
History
Wed, 15 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Apr 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator Developer (Administrator) roles, resulting in privilege escalation with potential for modification of simulation parameters, training configuration, and training records. | |
| Title | AVEVA Pipeline Simulation Missing Authorization | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-04-15T17:38:50.678Z
Reserved: 2026-04-01T21:04:13.517Z
Link: CVE-2026-5387
Updated: 2026-04-15T17:38:43.814Z
Status : Received
Published: 2026-04-15T16:16:39.007
Modified: 2026-04-15T16:16:39.007
Link: CVE-2026-5387
No data.
OpenCVE Enrichment
No data.