Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

AVEVA — Vulnerabilities & Security Advisories 51

Browse all 51 CVE security advisories affecting AVEVA. AI-powered Chinese analysis, POCs, and references for each vulnerability.

AVEVA provides industrial software solutions, primarily focusing on process simulation, asset performance management, and engineering design for sectors like oil and gas, chemicals, and pharmaceuticals. Its platform integrates complex operational technology with enterprise information systems, creating a broad attack surface for cyber threats. Historical vulnerability assessments reveal a prevalence of remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from legacy components or improper input validation within its web-based interfaces. While no catastrophic public breaches have been widely attributed solely to AVEVA software, the high volume of recorded CVEs indicates persistent security hygiene challenges. These defects frequently allow unauthenticated attackers to gain unauthorized access or disrupt critical industrial operations, underscoring the necessity for rigorous patch management and network segmentation in environments utilizing these industrial control systems.

CVE ID Title CVSS Severity Published
CVE-2026-81821 AVEVA Pipeline Integrity Monitor Use of hard-coded cryptographic key — Pipeline Integrity Monitor CWE-321 8.4 High 2026-09-08
CVE-2026-81822 AVEVA Pipeline Integrity Monitor Use of a Broken or Risky Cryptographic Algorithm — Pipeline Integrity Monitor CWE-327 8.4 High 2026-09-08
CVE-2026-81823 AVEVA Pipeline Integrity Monitor Missing Authorization — Pipeline Integrity Monitor CWE-862 5.3 Medium 2026-09-08
CVE-2026-81824 AVEVA Pipeline Integrity Monitor cross-site scripting — Pipeline Integrity Monitor CWE-79 4.7 Medium 2026-09-08
CVE-2025-7639 AVEVA Enterprise SCADA Deserialization of Untrusted Data — AVEVA Enterprise SCADA CWE-502 7.1 High 2026-08-14
CVE-2026-5387 AVEVA Pipeline Simulation Missing Authorization — Pipeline Simulation 2025 CWE-862 9.8 - 2026-04-15
CVE-2026-1507 Uncaught Exception vulnerability in AVEVA PI Data Archive — PI Data Archive PI Server CWE-248 7.5 High 2026-02-10
CVE-2026-1495 Insertion of Sensitive Information into Log File vulnerability in AVEVA PI to CONNECT Agent — PI to CONNECT Agent CWE-532 6.5 Medium 2026-02-10
CVE-2025-64769 AVEVA Process Optimization Cleartext Transmission of Sensitive Information — Process Optimization CWE-319 7.1 High 2026-01-16
CVE-2025-65117 AVEVA Process Optimization Use of Potentially Dangerous Function — Process Optimization CWE-676 7.4 High 2026-01-16
CVE-2025-64729 AVEVA Process Optimization Missing Authorization — Process Optimization CWE-862 8.1 High 2026-01-16
CVE-2025-65118 AVEVA Process Optimization Uncontrolled Search Path Element — Process Optimization CWE-427 8.8 High 2026-01-16
CVE-2025-61943 AVEVA Process Optimization SQL Injection — Process Optimization CWE-89 8.4 High 2026-01-16
CVE-2025-64691 AVEVA Process Optimization Code Injection — Process Optimization CWE-94 8.8 High 2026-01-16
CVE-2025-61937 AVEVA Process Optimization Code Injection — Process Optimization CWE-94 10.0 Critical 2026-01-16
CVE-2025-8386 AVEVA Application Server IDE Basic Cross-site Scripting — Application Server CWE-80 6.9 Medium 2025-11-14
CVE-2025-9317 AVEVA Edge Use of a Broken or Risky Cryptographic Algorithm — Edge CWE-327 8.4 High 2025-11-14
CVE-2025-54460 AVEVA PI Integrator Unrestricted Upload of File with Dangerous Type — PI Integrator CWE-434 7.1 High 2025-08-21
CVE-2025-41415 AVEVA PI Integrator Insertion of Sensitive Information into Sent Data — PI Integrator CWE-201 6.5 Medium 2025-08-21
CVE-2025-36539 AVEVA PI Data Archive Uncaught Exception — PI Data Archive CWE-248 6.5 Medium 2025-06-12
CVE-2025-44019 AVEVA PI Data Archive Uncaught Exception — PI Data Archive CWE-248 7.1 High 2025-06-12
CVE-2025-2745 AVEVA PI Web API Cross-site Scripting — PI Web API CWE-79 6.5 Medium 2025-06-12
CVE-2025-4418 AVEVA PI Connector for CygNet Improper Validation of Integrity Check Value — PI Connector for CygNet CWE-354 4.4 Medium 2025-06-12
CVE-2025-4417 AVEVA PI Connector for CygNet Cross-site Scripting — PI Connector for CygNet CWE-79 5.5 Medium 2025-06-12
CVE-2024-6456 SQL Injection vulnerability in AVEVA Historian Server — Historian Web Server CWE-89 8.8AI High AI 2024-08-15
CVE-2024-7113 Allocation of Resources Without Limits or Throttling in AVEVA SuiteLink Server — SuiteLink Server CWE-770 4.3AI Medium AI 2024-08-13
CVE-2024-3468 Deserialization of Untrusted Data in AVEVA PI Web API — PI Web API CWE-502 8.8AI High AI 2024-06-12
CVE-2024-3467 Deserialization of Untrusted Data in AVEVA PI Asset Framework Client — PI Asset Framework Client CWE-502 8.8AI High AI 2024-06-12
CVE-2023-6132 AVEVA Edge products Uncontrolled Search Path Element — AVEVA Edge CWE-427 7.3 High 2024-02-29
CVE-2023-34348 Improper Check or Handling of Exceptional Conditions in Aveva PI Server — PI Server CWE-703 7.5 High 2024-01-18

This page lists every published CVE security advisory associated with AVEVA. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.