A cross-site scripting vulnerability exists in
AVEVA PI Connector for CygNet
Versions 1.6.14 and prior that, if exploited, could allow an
administrator miscreant with local access to the connector admin portal
to persist arbitrary JavaScript code that will be executed by other
users who visit affected pages.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-18216 A cross-site scripting vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited, could allow an administrator miscreant with local access to the connector admin portal to persist arbitrary JavaScript code that will be executed by other users who visit affected pages.
Fixes

Solution

AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Users of affected product versions should apply security updates to mitigate the risk of exploit. All affected versions of PI Connector for CygNet can be fixed by upgrading to PI Connector for CygNet v1.7.0 or higher. From OSISoft Customer Portal https://my.osisoft.com/ , search for "PI Connector for CygNet" and select Version 1.7.0 or higher. For additional information please refer to AVEVA-2025-002 https://www.aveva.com/en/support-and-success/cyber-security-updates/ .


Workaround

AVEVA further recommends users follow general defensive measures: * Ensure that PI Connector for CygNet administrative access is only provided to trusted entities. * Audit custom installation folder Access Control Lists (ACLs) to ensure access is only provided to trusted entities. * Audit and limit membership to the OS Local "Administrators" and "PI Connector Administrators" groups. For additional information please refer to AVEVA-2025-002 https://www.aveva.com/en/support-and-success/cyber-security-updates/ .

History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00019}

epss

{'score': 0.00021}


Thu, 12 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Jun 2025 19:45:00 +0000

Type Values Removed Values Added
Description A cross-site scripting vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited, could allow an administrator miscreant with local access to the connector admin portal to persist arbitrary JavaScript code that will be executed by other users who visit affected pages.
Title AVEVA PI Connector for CygNet Cross-site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-06-12T19:57:09.559Z

Reserved: 2025-05-07T18:16:54.504Z

Link: CVE-2025-4417

cve-icon Vulnrichment

Updated: 2025-06-12T19:56:11.392Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-12T20:15:21.760

Modified: 2025-06-16T12:32:18.840

Link: CVE-2025-4417

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses