CVE-2025-44019: Aveva Pi Data Archive
High severity, CVSS 7.1. EPSS: 0.5% chance of exploitation in the next 30 days.
AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI Data Archive subsystems, resulting in a denial of service. Depending on the timing of the crash, data present in snapshots/write cache may be lost.
Affected products
- Aveva Pi Data Archive: version 2023 only; version 2023 Patch 1 only
- Aveva Pi Server: version 2023 only; version 2023 Patch 1 only
Published 2025-06-12. Last modified 2026-06-17.