Vulnerability index

Browse CVEs

38 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pi Vision HIGH 7.3
CVE-2020-25163

A remote attacker with write access to PI ProcessBook files could inject code that is imported into OSIsoft PI Vision 2020 versions prior to 3.5.0. U…

Fix: 2020+
Fix from $1,950 2022-04-18
Pi Vision MEDIUM 6.5
CVE-2020-25167

OSIsoft PI Vision 2020 versions prior to 3.5.0 could disclose information to a user with insufficient privileges for an AF attribute.

Fix: 3.5.0+
Fix from $1,600 2022-04-18
Pi Vision MEDIUM 5.4
CVE-2021-43551

A remote attacker with write access to PI Vision could inject code into a display. Unauthorized information disclosure, modification, or deletion is …

Fix: 2021+
Fix from $1,600 2021-11-17
Pi Vision MEDIUM 5.4
CVE-2020-10643

An authenticated remote attacker could use specially crafted URLs to send a victim using PI Vision 2019 mobile to a vulnerable web page due to a know…

No fix yet
Fix from $1,600 2020-07-27
Pi Data Archive HIGH 7.5
CVE-2020-10604

In OSIsoft PI System multiple products and versions, a remote, unauthenticated attacker could crash PI Network Manager service through specially craf…

Mitigation only
Fix from $1,950 2020-07-25
Pi Api HIGH 7.8
CVE-2020-10606

In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software. This expl…

Fix: after 4.8.0.18
Fix from $1,950 2020-07-24
Pi Api HIGH 7.8
CVE-2020-10608

In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libr…

Fix: after 4.8.0.18
Fix from $1,950 2020-07-24
Pi Api HIGH 7.8
CVE-2020-10610

In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System s…

Fix: after 4.8.0.18
Fix from $1,950 2020-07-24
Pi Data Archive HIGH 7.1
CVE-2020-10600

An authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. This can result in blocking qu…

Fix: after 2019
Fix from $1,950 2020-07-24
Pi Web Api CRITICAL 9.0
CVE-2020-12021

In OSIsoft PI Web API 2019 Patch 1 (1.12.0.6346) and all previous versions, the affected product is vulnerable to a cross-site scripting attack, whic…

Fix: after 2019
Fix from $2,300 2020-06-23
Pi Vision HIGH 8.8
CVE-2019-18271

OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to a cross-site request forgery that may be introduced…

Fix: 2019+
Fix from $1,950 2020-01-15
Pi Vision MEDIUM 6.5
CVE-2019-18275

OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to an improper access control, which may return unauth…

Fix: 2019+
Fix from $1,600 2020-01-15
Pi Web Api HIGH 8.8
CVE-2019-13516

In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forgery protection setting that ha…

Fix: after 2018
Fix from $1,950 2019-08-15
Pi Web Api MEDIUM 6.5
CVE-2019-13515

OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information.

Fix: after 2018
Fix from $1,600 2019-08-15
Pi Coresight HIGH 8.8
CVE-2017-9641

PI Coresight 2016 R2 contains a cross-site request forgery vulnerability that may allow access to the PI system. OSIsoft recommends that users upgrad…

Fix: after 2016-r2
Fix from $1,950 2018-05-25
Pi Af Client MEDIUM 5.5
CVE-2016-8365

OSIsoft PI System software (Applications using PI Asset Framework (AF) Client versions prior to PI AF Client 2016, Version 2.8.0; Applications using …

Fix: 1.4.6 / 2.8.0+
Fix from $1,600 2018-04-03
Pi Web Api CRITICAL 9.8
CVE-2018-7500

A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Privileges may be escalated, gi…

Fix: after 2017
Fix from $2,300 2018-03-14
Pi Data Archive HIGH 7.8
CVE-2018-7533

An Incorrect Default Permissions issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Insecure default configuration may allow es…

Fix: after 2017
Fix from $1,950 2018-03-14
Pi Data Archive HIGH 7.5
CVE-2018-7529

A Deserialization of Untrusted Data issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Unauthenticated users may modify deseria…

Fix: after 2017
Fix from $1,950 2018-03-14
Pi Vision MEDIUM 6.1
CVE-2018-7504

A Protection Mechanism Failure issue was discovered in OSIsoft PI Vision versions 2017 and prior. The X-XSS-Protection response header is not set to …

Fix: after 2017
Fix from $1,600 2018-03-14
Pi Web Api MEDIUM 6.1
CVE-2018-7508

A Cross-site Scripting issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Cross-site scripting may occur when input is incorrectl…

Fix: after 2017
Fix from $1,600 2018-03-14
Pi Data Archive MEDIUM 5.9
CVE-2018-7531

An Improper Input Validation issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Unauthenticated users may use unvalidated custo…

Fix: after 2017
Fix from $1,600 2018-03-14
Pi Vision MEDIUM 5.3
CVE-2018-7496

An Information Exposure issue was discovered in OSIsoft PI Vision versions 2017 and prior. The server response header and referrer-policy response he…

Fix: after 2017
Fix from $1,600 2018-03-14
Pi Web Api HIGH 8.8
CVE-2017-7926

A Cross-Site Request Forgery issue was discovered in OSIsoft PI Web API versions prior to 2017 (1.9.0). The vulnerability allows cross-site request f…

Mitigation only
Fix from $1,950 2017-08-25
Pi Data Archive HIGH 7.4
CVE-2017-7930

An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Data Archive has protocol flaws …

Fix: after 3.4.410.1256
Fix from $1,950 2017-08-25
Pi Data Archive MEDIUM 5.9
CVE-2017-7934

An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Network Manager using older prot…

Fix: after 3.4.410.1256
Fix from $1,600 2017-08-25
Pi Integrator For Business Analystics CRITICAL 9.8
CVE-2017-9653

An Improper Authorization issue was discovered in OSIsoft PI Integrator for Business Analytics before 2016 R2, PI Integrator for Microsoft Azure befo…

Mitigation only
Fix from $2,300 2017-08-14
Pi Integrator For Business Analystics MEDIUM 5.4
CVE-2017-9655

A Cross-Site Scripting issue was discovered in OSIsoft PI Integrator for Business Analytics before 2016 R2, PI Integrator for Microsoft Azure before …

Fix: after 2016
Fix from $1,600 2017-08-14
Pi Coresight HIGH 7.8
CVE-2017-5153

An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using the PI AF Services 2016 R2 i…

Fix: after 2016-r2
Fix from $1,950 2017-02-13
Pi Web Api 2015 R2 MEDIUM 6.4
CVE-2016-8353

An issue was discovered in OSIsoft PI Web API 2015 R2 (Version 1.5.1). There is a weakness in this product that may allow an attacker to access the P…

No fix yet
Fix from $1,600 2017-02-13