IM
IronMonkey Threat Research

CVE-2025-44019 HIGH

Published: 2025-06-12 | Last Modified: 2026-04-15 | Status: Deferred

Description

AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI Data Archive subsystems, resulting in a denial of service. Depending on the timing of the crash, data present in snapshots/write cache may be lost.

Additional Descriptions (1)

Los productos AVEVA PI Data Archive son vulnerables a una excepción no detectada que, de ser explotada, podría permitir que un usuario autenticado cierre ciertos subsistemas necesarios de PI Data Archive, lo que resultaría en una denegación de servicio. Dependiendo del momento del fallo, podrían perderse los datos presentes en las instantáneas o la caché de escritura.

CVSS Metrics

Base Score: 7.1 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactLOW
Availability ImpactHIGH

Source: [email protected]

Type: Secondary

Exploitability Score: 2.8

Impact Score: 4.2

Base Score: 7.1 (HIGH)

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack VectorNETWORK
Attack ComplexityLOW
Attack RequirementsNONE
Privileges RequiredLOW
User InteractionNONE
Vulnerability ConfidentialityNONE
Vulnerability IntegrityLOW
Vulnerability AvailabilityHIGH
Subsequent ConfidentialityNONE
Subsequent IntegrityNONE
Subsequent AvailabilityNONE

Source: [email protected]

Type: Secondary

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-248
Notification
Message here