CVE-2025-44019: AVEVA PI Data Archive Uncaught Exception
AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI Data Archive subsystems, resulting in a denial of service. Depending on the timing of the crash, data present in snapshots/write cache may be lost.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44019?
CVE-2025-44019 is classified as a denial of service vulnerability that affects AVEVA PI Data Archive products.
How do I fix CVE-2025-44019?
To mitigate CVE-2025-44019, upgrade to the latest patched version of AVEVA PI Data Archive or PI Server.
What products are affected by CVE-2025-44019?
CVE-2025-44019 affects AVEVA PI Data Archive Versions 2018 SP3 Patch 4 and prior, along with specific 2023 versions.
What could be the impact of exploiting CVE-2025-44019?
Exploiting CVE-2025-44019 could allow an authenticated user to shut down critical PI Data Archive subsystems, leading to service interruptions.
Is authentication required to exploit CVE-2025-44019?
Yes, exploiting CVE-2025-44019 requires authentication to the AVEVA PI Data Archive system.