CVE-2018-7533
Summary
| CVE | CVE-2018-7533 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-14 18:29:00 UTC |
| Updated | 2019-10-09 23:42:00 UTC |
| Description | An Incorrect Default Permissions issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Insecure default configuration may allow escalation of privileges that gives the actor full control over the system. |
Risk And Classification
Problem Types: CWE-276
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Osisoft | Pi Data Archive | 2017 | r2 | All | All |
| Application | Osisoft | Pi Data Archive | 2017 | r2 | All | All |
| Application | Osisoft | Pi Data Archive | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| OSIsoft PI Data Archive | CISA | MISC | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| OSIsoft PI Data Archive Privilege Escalation and Denial of Service Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.