CVE-2025-36539: Aveva Pi Data Archive

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI Data Archive subsystems, resulting in a denial of service.

Affected products

  • Aveva Pi Data Archive: version 2023 Patch 1 only
  • Aveva Pi Server

Published 2025-06-12. Last modified 2026-06-17.