CVE-2025-44019: AVEVA PI Data Archive Uncaught Exception

Published Jun 12, 2025
·
Updated

AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI Data Archive subsystems, resulting in a denial of service. Depending on the timing of the crash, data present in snapshots/write cache may be lost.

Affected Software

6 affected components
: AVEVA PI Data Archive: Versions 2018 SP3 Patch 4 and prior (CVE-2025-44019)
: AVEVA PI Data Archive: Version 2023 (CVE-2025-44019, CVE-2025-36539)
: AVEVA PI Data Archive: Version 2023 Patch 1 (CVE-2025-44019, CVE-2025-36539)
: AVEVA PI Server: Versions 2018 SP3 Patch 6 and prior (CVE-2025-44019)
: AVEVA PI Server: Version 2023 (CVE-2025-44019, CVE-2025-36539)
: AVEVA PI Server: Version 2023 Patch 1 (CVE-2025-44019, CVE-2025-36539)

Remediation

Information

AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Users with affected product versions should apply security updates to mitigate the risk of exploit. All affected versions of PI Data Archive and PI Server can be fixed by upgrading to PI Server 2024 or higher. From OSISoft Customer Portal https://my.osisoft.com/ , search for "AVEVA PI Server" and select version 2024 or higher. PI Data Archive 2018 SP3 Patch 4 and all prior and PI Server 2018 SP3 Patch 6 and all prior can alternatively be fixed by upgrading to PI Server 2018 SP3 Patch 7 or higher. From OSISoft Customer Portal https://my.osisoft.com/ , search for "AVEVA PI Server" and select Version 2018 SP3 Patch 7 or higher. For additional information please refer to AVEVA-2025-001 https://www.aveva.com/en/support-and-success/cyber-security-updates/ .

Event History

Jun 12, 2025
CVE Published
via MITRE·07:51 PM
Data Sourced
via MITRE·07:51 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-44019?

CVE-2025-44019 is classified as a denial of service vulnerability that affects AVEVA PI Data Archive products.

2

How do I fix CVE-2025-44019?

To mitigate CVE-2025-44019, upgrade to the latest patched version of AVEVA PI Data Archive or PI Server.

3

What products are affected by CVE-2025-44019?

CVE-2025-44019 affects AVEVA PI Data Archive Versions 2018 SP3 Patch 4 and prior, along with specific 2023 versions.

4

What could be the impact of exploiting CVE-2025-44019?

Exploiting CVE-2025-44019 could allow an authenticated user to shut down critical PI Data Archive subsystems, leading to service interruptions.

5

Is authentication required to exploit CVE-2025-44019?

Yes, exploiting CVE-2025-44019 requires authentication to the AVEVA PI Data Archive system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203