File Upload Vulnerability in AVEVA's Text File and HDFS Publication Systems
CVE-2025-54460

7.1HIGH

Key Information:

Vendor

Aveva

Vendor
CVE Published:
21 August 2025

What is CVE-2025-54460?

A vulnerability exists within AVEVA's Text File and HDFS Publication Systems that could be exploited by authenticated users with specific privileges. If successfully targeted, these users could upload and retain malicious files on the system, potentially leading to unauthorized execution. This risk highlights the importance of implementing stringent validation measures to safeguard against unauthorized file uploads.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

PI Integrator 0 < 2020 R2 SP1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Maxime Escourbiac, Michelin CERT, and Adam Bertrand, Abicom for Michelin CERT reported these vulnerabilities to AVEVA.
.