Show filters
46 Total Results
Displaying 21-30 of 46
Sort by:
Attacker Value
Unknown
CVE-2019-18275
Disclosure Date: April 04, 2019 (last updated February 21, 2025)
OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to an improper access control, which may return unauthorized tag data when viewing analysis data reference attributes.
0
Attacker Value
Unknown
CVE-2017-9641
Disclosure Date: May 25, 2018 (last updated November 26, 2024)
PI Coresight 2016 R2 contains a cross-site request forgery vulnerability that may allow access to the PI system. OSIsoft recommends that users upgrade to PI Vision 2017 or greater to mitigate this vulnerability.
0
Attacker Value
Unknown
CVE-2016-8365
Disclosure Date: April 03, 2018 (last updated November 26, 2024)
OSIsoft PI System software (Applications using PI Asset Framework (AF) Client versions prior to PI AF Client 2016, Version 2.8.0; Applications using PI Software Development Kit (SDK) versions prior to PI SDK 2016, Version 1.4.6; PI Buffer Subsystem, versions prior to and including, Version 4.4; and PI Data Archive versions prior to PI Data Archive 2015, Version 3.4.395.64) operates between endpoints without a complete model of endpoint features potentially causing the product to perform actions based on this incomplete model, which could result in a denial of service. OSIsoft reports that in order to exploit the vulnerability an attacker would need to be locally connected to a server. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H)
0
Attacker Value
Unknown
CVE-2018-7500
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Privileges may be escalated, giving attackers access to the PI System via the service account.
0
Attacker Value
Unknown
CVE-2018-7529
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
A Deserialization of Untrusted Data issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Unauthenticated users may modify deserialized data to send custom requests that crash the server.
0
Attacker Value
Unknown
CVE-2018-7496
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
An Information Exposure issue was discovered in OSIsoft PI Vision versions 2017 and prior. The server response header and referrer-policy response header each provide unintended information disclosure.
0
Attacker Value
Unknown
CVE-2018-7531
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
An Improper Input Validation issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Unauthenticated users may use unvalidated custom requests to crash the server.
0
Attacker Value
Unknown
CVE-2018-7508
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
A Cross-site Scripting issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Cross-site scripting may occur when input is incorrectly neutralized.
0
Attacker Value
Unknown
CVE-2018-7504
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
A Protection Mechanism Failure issue was discovered in OSIsoft PI Vision versions 2017 and prior. The X-XSS-Protection response header is not set to block, allowing attempts at reflected cross-site scripting.
0
Attacker Value
Unknown
CVE-2018-7533
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
An Incorrect Default Permissions issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Insecure default configuration may allow escalation of privileges that gives the actor full control over the system.
0