CVE-2025-41415

MEDIUM

AVEVA PI Integrator through 2020 R2 SP1 - Information Disclosure

Title source: llm
STIX 2.1

Description

The vulnerability, if exploited, could allow an authenticated miscreant (with privileges to access publication targets) to retrieve sensitive information that could then be used to gain additional access to downstream resources.

Scores

CVSS v3 6.5
EPSS 0.0005
EPSS Percentile 14.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-201
Status published
Products (1)
AVEVA/PI Integrator < 2020 R2 SP1
Published Aug 21, 2025
Tracked Since Feb 18, 2026