CVE-2025-54460: AVEVA PI Integrator Unrestricted Upload of File with Dangerous Type
The vulnerability, if exploited, could allow an authenticated miscreant (with privileges to create or access publication targets of type Text File or HDFS) to upload and persist files that could potentially be executed.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54460?
CVE-2025-54460 is considered a significant vulnerability due to its potential for authenticated users to upload and execute malicious files.
How do I fix CVE-2025-54460?
To mitigate CVE-2025-54460, upgrade to a patched version of AVEVA PI Integrator for Business Analytics beyond 2020 R2 SP1.
Who is affected by CVE-2025-54460?
CVE-2025-54460 affects users of AVEVA PI Integrator for Business Analytics versions 2020 R2 SP1 and earlier.
What can an attacker do with CVE-2025-54460?
An attacker exploiting CVE-2025-54460 could upload files that may allow for remote code execution under certain conditions.
Is there a public advisory for CVE-2025-54460?
Yes, public advisories regarding CVE-2025-54460 can be found through AVEVA's security bulletin and other cybersecurity resources.