CVE-2023-31274: Missing Release of Resource after Effective Lifetime vulnerability in Aveva PI Server
AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to cause the PI Message Subsystem of a PI Server to consume available memory resulting in throttled processing of new PI Data Archive events and a partial denial-of-service condition.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-31274?
CVE-2023-31274 is classified as a high-severity vulnerability allowing memory consumption that could lead to partial denial of service for the PI Message Subsystem.
How do I fix CVE-2023-31274?
To resolve CVE-2023-31274, you should upgrade to AVEVA PI Server version beyond 2018 SP3 P05 or 2023.
Which versions of AVEVA PI Server are affected by CVE-2023-31274?
CVE-2023-31274 affects AVEVA PI Server versions 2023, and 2018 SP3 P05 and earlier.
Can CVE-2023-31274 be exploited by authenticated users?
CVE-2023-31274 can be exploited by unauthenticated users, leading to potential denial of service.
What impact does CVE-2023-31274 have on system performance?
CVE-2023-31274 can cause the PI Message Subsystem to consume available memory, resulting in throttled processing of PI Data Archive events.