OSISoft PI System Encryption Security Bypass Vulnerability
BID:36553
Info
OSISoft PI System Encryption Security Bypass Vulnerability
| Bugtraq ID: | 36553 |
| Class: | Unknown |
| CVE: |
CVE-2009-0209 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2009 12:00AM |
| Updated: | Sep 30 2009 08:10PM |
| Credit: | Eyal Udassin, Jonathan Afek and Yaron Budowsky from C4 Security |
| Vulnerable: |
OSISoft PI System 0 |
| Not Vulnerable: | |
Discussion
OSISoft PI System Encryption Security Bypass Vulnerability
OSISoft PI System is prone to a security-bypass vulnerability.
An attacker can exploit this issue to gain access to the PI server database. Successful exploits will allow the attacker to obtain operational information and manipulate data on the server. Other attacks are also possible.
OSISoft PI System is prone to a security-bypass vulnerability.
An attacker can exploit this issue to gain access to the PI server database. Successful exploits will allow the attacker to obtain operational information and manipulate data on the server. Other attacks are also possible.
Exploit / POC
OSISoft PI System Encryption Security Bypass Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
OSISoft PI System Encryption Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
OSISoft PI System Encryption Security Bypass Vulnerability
References:
References:
- Vendor Homepage (OSISoft)
- C4_SCADA_Security_Advisory ('Eyal Udassin'
)