ICSA-25-162-09
·
Published 2025-06-12
·
View on CISA ICS-CERT ↗
AVEVA PI Connector for CygNet
CVSS 5.5
MEDIUM
Risk Summary
Successful exploitation of these vulnerabilities could allow an attacker to persist arbitrary code in the administrative portal of the product or cause a denial-of-service condition.
CVEs (2)
Remediations
- AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Customers using affected product versions should apply security updates to mitigate the risk of exploit.
- All affected versions of PI Connector for CygNet can be fixed by upgrading to PI Connector for CygNet v1.7.0 or higher. From OSISoft Customer Portal, search for "PI Connector for CygNet" and select Version 1.7.0 or higher.
- AVEVA further recommends users follow general defensive measures:
- Ensure that PI Connector for CygNet administrative access is only provided to trusted entities.
- Audit custom installation folder Access Control Lists (ACLs) to ensure access is only provided to trusted entities.
- Audit and limit membership to the OS Local "Administrators" and "PI Connector Administrators" groups.
- For additional information please refer to AVEVA-2025-002.
Affected Vendors
AVEVA
Affected Products (1)
AVEVA
·
PI Connector for CygNet
<=1.6.14
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more