CVE 6.5 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in AVEVA PI to CONNECT Agent_CVE-2026-1495

6.5 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Description

The vulnerability, if exploited, could allow an attacker with Event Log Reader (S-1-5-32-573) privileges to obtain proxy details, including URL and proxy credentials, from the PI to CONNECT event log files. This could enable unauthorized access to the proxy server.

Basic Information

ID CVE-2026-1495
Source icscert
Published Feb 10, 2026 at 20:18

Affected Product

Vendor AVEVA
Product PI to CONNECT Agent
Affected Versions AVEVA PI to CONNECT Agent 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.