CVE-2023-34348: Aveva Pi Server

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to remotely crash the PI Message Subsystem of a PI Server, resulting in a denial-of-service condition.

Affected products

  • Aveva Pi Server: before 2018 (fixed in 2018); version 2018 only; version 2023 only

Published 2024-01-18. Last modified 2026-06-17.