CVE Database
/

CVE-2025-44019

Back to search

CVE-2025-44019

Published: Jun 12, 2025

Modified: Jun 12, 2025

PUBLISHED

CVSS v3.1

7.1

HIGH

Description

AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI Data Archive subsystems, resulting in a denial of service. Depending on the timing of the crash, data present in snapshots/write cache may be lost.

VendorProductVersions

AVEVA

PI Data Archive

affected
0 - <= 2018 SP3 Patch 4

AVEVA

PI Data Archive

affected
2023

AVEVA

PI Data Archive

affected
2023 Patch 1

AVEVA

PI Server

affected
0 - <= 2018 SP3 Patch 6

AVEVA

PI Server

affected
2023

AVEVA

PI Server

affected
2023 Patch 1

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

Low

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now