The vulnerability, if exploited, could allow an authenticated miscreant
(with privileges to create or access publication targets of type Text
File or HDFS) to upload and persist files that could potentially be
executed.
Metrics
Affected Vendors & Products
References
History
Fri, 22 Aug 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 Aug 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The vulnerability, if exploited, could allow an authenticated miscreant (with privileges to create or access publication targets of type Text File or HDFS) to upload and persist files that could potentially be executed. | |
| Title | AVEVA PI Integrator Unrestricted Upload of File with Dangerous Type | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published: 2025-08-21T20:00:11.036Z
Updated: 2025-08-21T20:13:06.036Z
Reserved: 2025-07-31T16:41:30.389Z
Link: CVE-2025-54460
Updated: 2025-08-21T20:13:00.514Z
Status : Awaiting Analysis
Published: 2025-08-21T20:15:45.883
Modified: 2025-08-22T18:08:51.663
Link: CVE-2025-54460
No data.