CVE-2025-54460
BaseFortify
Publication date: 2025-08-21
Last updated on: 2025-08-22
Assigner: ICS-CERT
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| aveva | pi_integrator_for_business_analytics | 2020_r2_sp1 |
| aveva | pi_integrator_for_business_analytics | 2020_r2_sp2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-434 | The product allows the upload or transfer of dangerous file types that are automatically processed within its environment. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability allows an authenticated user with privileges to create or access publication targets of type Text File or HDFS to upload and persist files that could potentially be executed. Essentially, a user with certain access rights could place executable files on the system, which might lead to unauthorized code execution.
How can this vulnerability impact me? :
If exploited, this vulnerability could lead to unauthorized execution of files on the affected system. This could result in potential compromise of system integrity, unauthorized actions, or further exploitation by attackers leveraging the ability to run malicious code.