AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to remotely crash the PI Message Subsystem of a PI Server, resulting in a denial-of-service condition.
The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pi_server | Aveva | * | 2018 (excluding) |
Pi_server | Aveva | 2018 (including) | 2018 (including) |
Pi_server | Aveva | 2018-sp3_patch_5 (including) | 2018-sp3_patch_5 (including) |
Pi_server | Aveva | 2023 (including) | 2023 (including) |