CNNVD-202506-1710 Information

CNNVD ID

CNNVD-202506-1710

CVE-2025-4418

  • CNNVD Published: 2025-06-12

Description (Chinese)

AVEVA PI Connector for CygNet是英国AVEVA公司的一个提供从CygNet SCADA系统到PI系统的单向数据传输的工具。 AVEVA PI Connector for CygNet 1.6.14及之前版本存在安全漏洞,该漏洞源于完整性检查值验证不当,可能导致服务无响应。

Description (English)

AVEVA PI Contractor for CygNet is a one-way data transfer from the CygNet SCADA system to the PI system by the British company AVEVA. AVEVA PI Contractor for CygNet 1.6.14 and previous versions had a security loophole, which stemmed from inadequate integrity verification and could lead to unresponsive services.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

剑维软件

Published

2025-06-12

Last Modified

2026-02-24

References

https://www.aveva.com/en/support-and-success/cyber-security-updates/ https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-09 https://access.redhat.com/security/cve/cve-2025-4418

Patch

https://www.aveva.com/en/support-and-success/cyber-security-updates/

Share on: