CVE-2025-44019
BaseFortify
Publication date: 2025-06-12
Last updated on: 2025-06-16
Assigner: ICS-CERT
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-248 | An exception is thrown from a function, but it is not caught. |
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :
The impact of this vulnerability includes denial of service due to shutdown of critical PI Data Archive subsystems. Additionally, there is a risk of data loss from snapshots or write cache depending on the timing of the crash.
Can you explain this vulnerability to me?
This vulnerability in AVEVA PI Data Archive products involves an uncaught exception that can be exploited by an authenticated user to shut down certain necessary PI Data Archive subsystems. This shutdown results in a denial of service, and depending on when the crash occurs, data in snapshots or the write cache may be lost.