CVE-2023-31274: Aveva Pi Server

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to cause the PI Message Subsystem of a PI Server to consume available memory resulting in throttled processing of new PI Data Archive events and a partial denial-of-service condition.

Affected products

  • Aveva Pi Server: before 2018 (fixed in 2018); version 2018 only; version 2023 only

Published 2024-01-18. Last modified 2026-06-17.