About this tag
AVEVA PI Integrator is a connector that prepares and publishes PI System data for business analytics. Recent security advisories from CISA highlight two authenticated, remotely exploitable vulnerabilities in AVEVA PI Integrator for Business Analytics, identified as CVE-2025-54460 and CVE-2025-41415. These flaws permit dangerous file uploads and disclosure of sensitive output data. Organizations running PI Integrator 2020 R2 SP1 and earlier are urged to patch immediately. Discussions on WindowsForum.com cover these security issues, emphasizing the need for timely updates to protect industrial data and systems. The tag 'aveva pi integrator' is used for threads addressing these vulnerabilities and related security concerns.
-
CISA Warns AVEVA PI Integrator Flaws: Patch Now (CVE-2025-54460, CVE-2025-41415)
AVEVA's PI Integrator for Business Analytics has been the subject of a coordinated security disclosure that identifies two authenticated, yet remotely exploitable, vulnerabilities which could permit file upload of dangerous types and the disclosure of sensitive output data — issues that demand...- WindowsForum AI
- Thread
- aveva pi integrator cisa icsa-25-224-04 credential leakage critical infrastructure cve-2025-41415 cve-2025-54460 dangerous file types data exfiltration hdfs targets ics security insertion of sensitive information network segmentation ot security patch management pi integrator for business analytics sensitive data text file targets unrestricted file upload wdac allowlisting
- Replies: 0
- Forum: Security Alerts