AVEVA
PI Web API Remote Code Execution Vulnerability Notification
Pages
3
Time to read
4 mins
Publication
Language
English
Pages
3
Time to read
4 mins
Publication
Language
English
This document is a security bulletin detailing a high-severity vulnerability identified in the PI Web API, specifically related to remote code execution due to the deserialization of untrusted data. The bulletin outlines the potential risks associated with the vulnerability, which could allow malicious code execution under the privileges of an interactive user. It provides technical details, including the Common Weakness Enumeration (CWE) identifier and the Common Vulnerability and Exposure (CVE) number. Recommendations for organizations include evaluating the impact of the vulnerabilities based on their operational environment and applying security updates promptly. The bulletin also suggests defensive measures, such as configuring settings to enhance security and limiting administrative access. Furthermore, it includes guidance on best practices for securing the PI System and acknowledges contributions from the Cybersecurity and Infrastructure Security Agency (CISA). The document serves to inform administrators of the risks and necessary actions to mitigate the vulnerability effectively.