AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to remotely crash the PI Message Subsystem of a PI Server, resulting in a denial-of-service condition.




Fixes

Solution

All affected versions can be fixed by upgrading to AVEVA PI Server version 2023 Patch 1 or later. From OSI Soft Customer Portal https://my.osisoft.com/ , search for “PI Server” and select version “2023 Patch 1”. For an alternative fix, AVEVA PI Server 2018 SP3 Patch 5 and prior can be fixed by deploying AVEVA PI Server version 2018 SP3 Patch 6 or later. From OSI Soft Customer Portal https://my.osisoft.com/ , search for “PI Server” and select version “2018 SP3 Patch 6”. AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Customers using affected products should apply security updates as soon as possible. AVEVA recommends the following defensive measures: * Set the PI Message Subsystem to auto restart. * Monitor the memory usage of the PI Message Subsystem. * Limit network access to port 5450 to trusted workstations and software * Confirm that only authorized users have access to write to the PI Server Message Log. This is done through configuration of the PIMSGSS entry within the Database Security plugin accessible through PI System Management Tools. For more information on this vulnerability, including security updates, users should see security bulletin AVEVA-2024-001 https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2024-001.pdf .


Workaround

No workaround given by the vendor.

History

Mon, 21 Oct 2024 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-754
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-10-21T11:44:39.250Z

Reserved: 2023-07-12T18:40:13.110Z

Link: CVE-2023-34348

cve-icon Vulnrichment

Updated: 2024-08-02T16:10:06.138Z

cve-icon NVD

Status : Modified

Published: 2024-01-18T18:15:08.457

Modified: 2024-11-21T08:07:03.940

Link: CVE-2023-34348

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.