- What is the severity of CVE-2025-44019?
- CVE-2025-44019 has been scored as a high severity vulnerability.
- How to fix CVE-2025-44019?
- To fix CVE-2025-44019: AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Users with affected product versions should apply security updates to mitigate the risk of exploit. All affected versions of PI Data Archive and PI Server can be fixed by upgrading to PI Server 2024 or higher. From OSISoft Customer Portal https://my.osisoft.com/ , search for "AVEVA PI Server" and select version 2024 or higher. PI Data Archive 2018 SP3 Patch 4 and all prior and PI Server 2018 SP3 Patch 6 and all prior can alternatively be fixed by upgrading to PI Server 2018 SP3 Patch 7 or higher. From OSISoft Customer Portal https://my.osisoft.com/ , search for "AVEVA PI Server" and select Version 2018 SP3 Patch 7 or higher. For additional information please refer to AVEVA-2025-001 https://www.aveva.com/en/support-and-success/cyber-security-updates/ .
- Is CVE-2025-44019 being actively exploited in the wild?
- As for now, there are no information to confirm that CVE-2025-44019 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
- What software or system is affected by CVE-2025-44019?
- CVE-2025-44019 affects AVEVA PI Data Archive, AVEVA PI Data Archive, AVEVA PI Data Archive, AVEVA PI Server, AVEVA PI Server, AVEVA PI Server.