QID 590604
Date Published: 2021-12-01
QID 590604: OSIsoft PI Web API Cross-Site Scripting (XSS) Vulnerability (ICSA-21-313-06)
AFFECTED PRODUCTS
The following versions of PI Web API, a data management platform, are affected:
All versions of PI Web API 2019 SPI and prior
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of PIvision using registry "HKLM\SOFTWARE\PISystem"
Successful exploitation of this vulnerability could allow a remote authenticated attacker access to sensitive information or deliver false information.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-21-313-06 for affected packages and patching details.
Vendor References
- ICSA-21-313-06 -
www.us-cert.gov/ics/advisories/ICSA-21-313-06
CVEs related to QID 590604
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-21-313-06 |
|