CVE-2021-43549
Summary
| CVE | CVE-2021-43549 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-18 15:15:00 UTC |
| Updated | 2021-11-23 17:09:00 UTC |
| Description | A remote authenticated attacker with write access to a PI Server could trick a user into interacting with a PI Web API endpoint and redirect them to a malicious website. As a result, a victim may disclose sensitive information to the attacker or be provided with false information. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Osisoft |
Pi Web Api |
All |
All |
All |
All |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590604 OSIsoft PI Web API Cross-Site Scripting (XSS) Vulnerability (ICSA-21-313-06)