CVE-2025-54460
7.1AVEVA · PI Integrator for Business Analytics
An authenticated file upload vulnerability in AVEVA PI Integrator for Business Analytics allows attackers to upload and persist files that may lead to arbitrary code execution.
Executive summary
An authenticated file upload vulnerability in AVEVA PI Integrator for Business Analytics poses a significant risk of unauthorized file persistence and potential code execution.
Vulnerability
This vulnerability is a CWE-434 flaw involving unrestricted file uploads. An authenticated user with privileges to access or create Text File or HDFS publication targets can upload malicious files to the system.
Business impact
Successful exploitation allows an authenticated attacker to persist malicious files, which may subsequently be executed by the system. Given the CVSS score of 7.1, this vulnerability represents a high risk to operational integrity, potentially leading to unauthorized system control or lateral movement within the production environment.
Remediation
Immediate Action: Upgrade to PI Integrator for Business Analytics version 2020 R2 SP2 or higher via the official AVEVA customer portal.
Proactive Monitoring: Review system access logs for unusual file upload activities or unauthorized access to publication target configurations.
Compensating Controls: Implement strict access controls for publication targets and utilize file integrity monitoring to detect unauthorized file persistence on the server.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability necessitates immediate attention to prevent potential code execution. Administrators should prioritize updating the affected PI Integrator instances to the recommended version to eliminate the underlying file upload flaw and secure the environment against unauthorized persistence.
Sources
Originally found and disclosed by Maxime Escourbiac, Michelin CERT, and Adam Bertrand, Abicom for Michelin CERT reported these vulnerabilities to AVEVA., per the CVE Program record.