Show filters
46 Total Results
Displaying 1-10 of 46
Sort by:
Attacker Value
Unknown

CVE-2022-27893

Disclosure Date: November 04, 2022 (last updated December 22, 2024)
The Foundry Magritte plugin osisoft-pi-web-connector versions 0.15.0 - 0.43.0 was found to be logging in a manner that captured authentication requests. This vulnerability is resolved in osisoft-pi-web-connector version 0.44.0.
Attacker Value
Unknown

CVE-2020-25167

Disclosure Date: April 18, 2022 (last updated October 07, 2023)
OSIsoft PI Vision 2020 versions prior to 3.5.0 could disclose information to a user with insufficient privileges for an AF attribute.
Attacker Value
Unknown

CVE-2020-25163

Disclosure Date: April 18, 2022 (last updated October 07, 2023)
A remote attacker with write access to PI ProcessBook files could inject code that is imported into OSIsoft PI Vision 2020 versions prior to 3.5.0. Unauthorized information disclosure, modification, or deletion is also possible if a victim views or interacts with the infected display. This vulnerability affects PI System data and other data accessible with victim’s user permissions.
Attacker Value
Unknown

CVE-2021-43553

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
PI Vision could disclose information to a user with insufficient privileges for an AF attribute that is the child of another attribute and is configured as a Limits property.
Attacker Value
Unknown

CVE-2021-43551

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
A remote attacker with write access to PI Vision could inject code into a display. Unauthorized information disclosure, modification, or deletion is possible if a victim views or interacts with the infected display using Microsoft Internet Explorer. The impact affects PI System data and other data accessible with victim's user permissions.
Attacker Value
Unknown

CVE-2021-43549

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
A remote authenticated attacker with write access to a PI Server could trick a user into interacting with a PI Web API endpoint and redirect them to a malicious website. As a result, a victim may disclose sensitive information to the attacker or be provided with false information.
Attacker Value
Unknown

CVE-2020-10604

Disclosure Date: July 25, 2020 (last updated February 21, 2025)
In OSIsoft PI System multiple products and versions, a remote, unauthenticated attacker could crash PI Network Manager service through specially crafted requests. This can result in blocking connections and queries to PI Data Archive.
Attacker Value
Unknown

CVE-2020-10614

Disclosure Date: July 25, 2020 (last updated February 21, 2025)
In OSIsoft PI System multiple products and versions, an authenticated remote attacker with write access to PI Vision databases could inject code into a display. Unauthorized information disclosure, deletion, or modification is possible if a victim views the infected display.
Attacker Value
Unknown

CVE-2020-10608

Disclosure Date: July 24, 2020 (last updated February 21, 2025)
In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure, deletion, or modification.
Attacker Value
Unknown

CVE-2020-10610

Disclosure Date: July 24, 2020 (last updated February 21, 2025)
In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification.