PT-2025-25350 · Aveva · Aveva Pi Connector For Cygnet

Published

2025-06-12

·

Updated

2025-06-12

·

CVE-2025-4417

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions AVEVA PI Connector for CygNet versions 1.6.14 and prior
Description A cross-site scripting issue exists that could allow an administrator with local access to the connector admin portal to persist arbitrary JavaScript code, which will be executed by other users who visit affected pages.
Recommendations For versions 1.6.14 and prior, update to a version later than 1.6.14 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-08210
CVE-2025-4417

Affected Products

Aveva Pi Connector For Cygnet