← Back to home
ICSA-24-018-01  ·  Published 2024-01-18  ·  View on CISA ICS-CERT ↗

AVEVA PI Server

CVSS 7.5 HIGH

Risk Summary

Successful exploitation of these vulnerabilities could allow an attacker to crash the product being accessed or throttle the memory leading to a partial denial-of-service condition.

Remediations

  • All affected versions can be fixed by upgrading to AVEVA PI Server version 2023 Patch 1 or later. From OSI Soft Customer Portal, search for "PI Server" and select version "2023 Patch 1".
  • For an alternative fix, AVEVA PI Server 2018 SP3 Patch 5 and prior can be fixed by deploying AVEVA PI Server version 2018 SP3 Patch 6 or later. From OSI Soft Customer Portal, search for "PI Server" and select version "2018 SP3 Patch 6".
  • AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Customers using affected products should apply security updates as soon as possible.
  • AVEVA recommends the following defensive measures:
  • Set the PI Message Subsystem to auto restart.
  • Monitor the memory usage of the PI Message Subsystem.
  • Limit network access to port 5450 to trusted workstations and software
  • Confirm that only authorized users have access to write to the PI Server Message Log. This is done through configuration of the PIMSGSS entry within the Database Security plugin accessible through PI System Management Tools.
  • For more information on this vulnerability, including security updates, users should see security bulletin AVEVA-2024-001.

Affected Vendors

AVEVA

Affected Products (2)

AVEVA · PI Server 2023
AVEVA · PI Server <=2018_SP3_P05

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more