AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited,
could allow a miscreant with elevated privileges to modify PI Connector
for CygNet local data files (cache and buffers) in a way that causes the
connector service to become unresponsive.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18217 | An improper validation of integrity check value vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited, could allow a miscreant with elevated privileges to modify PI Connector for CygNet local data files (cache and buffers) in a way that causes the connector service to become unresponsive. |
Solution
AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Users of affected product versions should apply security updates to mitigate the risk of exploit. All affected versions of PI Connector for CygNet can be fixed by upgrading to PI Connector for CygNet v1.7.0 or higher. From OSISoft Customer Portal https://my.osisoft.com/ , search for "PI Connector for CygNet" and select Version 1.7.0 or higher. For additional information please refer to AVEVA-2025-002 https://www.aveva.com/en/support-and-success/cyber-security-updates/ .
Workaround
AVEVA further recommends users follow general defensive measures: * Ensure that PI Connector for CygNet administrative access is only provided to trusted entities. * Audit custom installation folder Access Control Lists (ACLs) to ensure access is only provided to trusted entities. * Audit and limit membership to the OS Local "Administrators" and "PI Connector Administrators" groups. For additional information please refer to AVEVA-2025-002 https://www.aveva.com/en/support-and-success/cyber-security-updates/ .
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 12 Jun 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Jun 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper validation of integrity check value vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited, could allow a miscreant with elevated privileges to modify PI Connector for CygNet local data files (cache and buffers) in a way that causes the connector service to become unresponsive. | |
| Title | AVEVA PI Connector for CygNet Improper Validation of Integrity Check Value | |
| Weaknesses | CWE-354 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-06-12T19:54:54.525Z
Reserved: 2025-05-07T18:16:55.551Z
Link: CVE-2025-4418
Updated: 2025-06-12T19:54:00.441Z
Status : Awaiting Analysis
Published: 2025-06-12T20:15:21.943
Modified: 2025-06-16T12:32:18.840
Link: CVE-2025-4418
No data.
OpenCVE Enrichment
No data.
EUVD