Description
An improper validation of integrity check value vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited, could allow a miscreant with elevated privileges to modify PI Connector for CygNet local data files (cache and buffers) in a way that causes the connector service to become unresponsive.
Problem types
Product status
Any version
Credits
AVEVA reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-162-09
www.aveva.com/en/support-and-success/cyber-security-updates/