Six publicly disclosed vulnerabilities across enterprise security, industrial control, and network-monitoring products. Summaries below are limited to details published by the vendors and coordinating authorities.
CVE-2026-20199
Cisco ThousandEyes Virtual Appliance
- Type: Command injection / authenticated remote code execution (CWE-74)
- Attack context: Remote, authenticated; valid administrative credentials required
- Severity: CVSS v3.1 4.7
- Summary: Insufficient validation in SSL certificate handling allows an administrator to upload a crafted certificate and execute commands as root on the appliance.
- Vendor advisory: Cisco Security Advisory cisco-sa-tevacert-rce-RMJVEym5
CVE-2025-2297
BeyondTrust Privilege Management for Windows
- Type: Privilege escalation through incorrect privilege assignment (CWE-268)
- Attack context: Local, authenticated; standard user with the ability to edit their profile files
- Severity: CVSS v4.0 7.2
- Summary: Before version 25.4.270.0, a user can manipulate profile files to place illegitimate challenge-response codes in the local user registry and elevate to administrator.
- Vendor advisory: BeyondTrust BT25-05
CVE-2024-0400
Hitachi Energy MACH SCM
- Type: Code injection leading to remote code execution (CWE-94)
- Attack context: Remote, authenticated client
- Severity: CVSS v3.1 7.5
- Summary: A malicious authenticated client can submit crafted code through SCM Server LINQ-query functionality, bypass validation, and execute arbitrary commands remotely on the server.
- Vendor advisory: Hitachi Energy advisory 8DBD000189
- Coordinating advisory: CISA ICSA-24-116-02
CVE-2024-2097
Hitachi Energy MACH SCM
- Type: Eval injection / improper neutralization in dynamically evaluated code (CWE-95)
- Attack context: Remote, authenticated List control client
- Severity: CVSS v3.1 7.5
- Summary: A malicious authenticated List control client can send a crafted LINQ query that SCM Server evaluates, allowing arbitrary code execution beyond the client’s intended authorization.
- Vendor advisory: Hitachi Energy advisory 8DBD000189
- Coordinating advisory: CISA ICSA-24-116-02
CVE-2023-33873
AVEVA Operations Control Logger used by multiple AVEVA products
- Type: Execution with unnecessary privileges / privilege escalation (CWE-250)
- Attack context: Local, OS-authenticated standard user
- Severity: CVSS v3.1 7.8
- Summary: A standard local user can exploit the logger’s excessive privileges to elevate to SYSTEM, resulting in complete compromise of the affected machine.
- Vendor advisory: AVEVA Security Bulletin AVEVA-2023-003 (PDF)
- Coordinating advisory: CISA ICSA-23-318-01
CVE-2023-34982
AVEVA Operations Control Logger used by multiple AVEVA products
- Type: External control of file name or path (CWE-73)
- Attack context: Local, OS-authenticated standard user
- Severity: CVSS v3.1 7.1
- Summary: A standard local user can cause files to be deleted with SYSTEM privileges on a machine running an affected product.
- Vendor advisory: AVEVA Security Bulletin AVEVA-2023-003 (PDF)
- Coordinating advisory: CISA ICSA-23-318-01