PT-2025-25354 · Aveva · Aveva Pi Server+1

Published

2025-06-10

·

Updated

2025-06-17

·

CVE-2025-44019

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions AVEVA PI Data Archive versions 2018 SP3 Patch 4 and earlier AVEVA PI Data Archive version 2023 AVEVA PI Data Archive version 2023 Patch 1 AVEVA PI Server versions 2018 SP3 Patch 6 and earlier AVEVA PI Server version 2023 AVEVA PI Server version 2023 Patch 1
Description The issue is related to an uncaught exception that could allow an authenticated user to shut down certain necessary PI Data Archive subsystems, resulting in a denial of service. Depending on the timing of the crash, data present in snapshots/write cache may be lost.
Recommendations For AVEVA PI Data Archive versions 2018 SP3 Patch 4 and earlier, update to a version later than 2018 SP3 Patch 4. For AVEVA PI Data Archive version 2023, apply the necessary patch or update to a later version. For AVEVA PI Data Archive version 2023 Patch 1, apply the necessary patch or update to a later version. For AVEVA PI Server versions 2018 SP3 Patch 6 and earlier, update to a version later than 2018 SP3 Patch 6. For AVEVA PI Server version 2023, apply the necessary patch or update to a later version. For AVEVA PI Server version 2023 Patch 1, apply the necessary patch or update to a later version.

Fix

DoS

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

BDU:2025-06711
CVE-2025-44019

Affected Products

Aveva Pi Data Archive
Aveva Pi Server