CVE-2025-41415: AVEVA PI Integrator Insertion of Sensitive Information into Sent Data
The vulnerability, if exploited, could allow an authenticated miscreant (with privileges to access publication targets) to retrieve sensitive information that could then be used to gain additional access to downstream resources.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41415?
CVE-2025-41415 is considered a high severity vulnerability that allows authenticated users to potentially access sensitive information.
How do I fix CVE-2025-41415?
To mitigate CVE-2025-41415, update the AVEVA PI Integrator for Business Analytics to a version later than 2020 R2 SP1.
Who is affected by CVE-2025-41415?
CVE-2025-41415 affects users of AVEVA PI Integrator for Business Analytics versions 2020 R2 SP1 and prior.
What type of information could be exposed in CVE-2025-41415?
CVE-2025-41415 could allow attackers to retrieve sensitive information leading to unauthorized access to downstream resources.
Can CVE-2025-41415 be exploited remotely?
CVE-2025-41415 requires authentication, meaning it cannot be exploited remotely by unauthenticated users.