CVE-2025-54460: Aveva Pi Integrator
High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.
The vulnerability, if exploited, could allow an authenticated miscreant (with privileges to create or access publication targets of type Text File or HDFS) to upload and persist files that could potentially be executed.
Affected products
- Aveva Pi Integrator: before 2020 R2 SP1 (fixed in 2020 R2 SP1)
Published 2025-08-21. Last modified 2026-06-17.