Vulnerabilities in AVEVA
55 resultsVexday analysis
A AVEVA apresenta um portfólio de 48 vulnerabilidades catalogadas, com 6 classificadas como críticas, porém nenhuma está sob exploração ativa no momento. A ausência de publicações nos últimos 90 dias indica que o risco atual é estável, embora a fraqueza dominante (CWE-427 - Validação inadequada de entrada) demande vigilância contínua na adoção de patches disponíveis para as vulnerabilidades críticas já conhecidas.
CVE-2023-34982MEDIUMAVEVA Operations Control Logger External Control of File Name or Path EPSS 0.2%CVE-2023-6132HIGHAVEVA Edge products Uncontrolled Search Path ElementEPSS 0.2%CVE-2025-64729HIGHAVEVA Process Optimization Missing AuthorizationEPSS 0.2%CVE-2024-3467HIGHDeserialization of Untrusted Data in AVEVA PI Asset Framework ClientEPSS 0.2%CVE-2021-32942MEDIUMThe vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorizEPSS 0.2%CVE-2025-64769HIGHAVEVA Process Optimization Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2022-0835HIGHAVEVA System Platform Cleartext Storage of Sensitive Information in MemoryEPSS 0.2%CVE-2025-8386HIGHAVEVA Application Server IDE Basic Cross-site ScriptingEPSS 0.2%CVE-2026-81821HIGHAVEVA Pipeline Integrity Monitor Use of hard-coded cryptographic keyEPSS 0.2%CVE-2025-4417MEDIUMAVEVA PI Connector for CygNet Cross-site ScriptingEPSS 0.1%CVE-2024-6619HIGHIncorrect Permission Assignment for Critical Resource in Ocean Data Systems Dream ReportEPSS 0.1%CVE-2026-1495MEDIUMInsertion of Sensitive Information into Log File vulnerability in AVEVA PI to CONNECT AgentEPSS 0.1%CVE-2026-81822HIGHAVEVA Pipeline Integrity Monitor Use of a Broken or Risky Cryptographic AlgorithmEPSS 0.1%CVE-2025-4418MEDIUMAVEVA PI Connector for CygNet Improper Validation of Integrity Check ValueEPSS 0.1%CVE-2025-9317HIGHAVEVA Edge Use of a Broken or Risky Cryptographic AlgorithmEPSS 0.1%