Known Vulnerabilities for products from Osisoft
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Osisoft".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-43553 json | PI Vision could disclose information to a user with insufficient privileges for an AF attribute that is the child of another ... | 4.3 - MEDIUM | 2021-11-17 | 2021-11-19 |
| CVE-2021-43551 json | A remote attacker with write access to PI Vision could inject code into a display. Unauthorized information disclosure, modif... | 5.4 - MEDIUM | 2021-11-17 | 2022-04-12 |
| CVE-2021-43549 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 4.8 - MEDIUM | 2021-11-18 | 2021-11-23 |
| CVE-2020-25167 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.5 - MEDIUM | 2022-04-18 | 2022-04-26 |
| CVE-2020-25163 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.3 - HIGH | 2022-04-18 | 2022-04-27 |
| CVE-2020-12021 json | In OSIsoft PI Web API 2019 Patch 1 (1.12.0.6346) and all previous versions, the affected product is vulnerable to a cross-sit... | 9 - CRITICAL | 2020-06-23 | 2020-07-02 |
| CVE-2020-10643 json | An authenticated remote attacker could use specially crafted URLs to send a victim using PI Vision 2019 mobile to a vulnerabl... | 5.4 - MEDIUM | 2020-07-27 | 2020-08-05 |
| CVE-2020-10614 json | In OSIsoft PI System multiple products and versions, an authenticated remote attacker with write access to PI Vision database... | 4.8 - MEDIUM | 2020-07-25 | 2020-08-05 |
| CVE-2020-10610 json | In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit ... | 7.8 - HIGH | 2020-07-24 | 2021-12-21 |
| CVE-2020-10608 json | In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check fo... | 7.8 - HIGH | 2020-07-24 | 2020-08-05 |
| CVE-2020-10606 json | In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI Sy... | 7.8 - HIGH | 2020-07-24 | 2020-08-05 |
| CVE-2020-10604 json | In OSIsoft PI System multiple products and versions, a remote, unauthenticated attacker could crash PI Network Manager servic... | 7.5 - HIGH | 2020-07-25 | 2022-10-21 |
| CVE-2020-10600 json | An authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. This c... | 7.1 - HIGH | 2020-07-24 | 2020-08-05 |
| CVE-2019-18275 json | OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to an improper access control,... | 6.5 - MEDIUM | 2020-01-15 | 2020-10-19 |
| CVE-2019-18273 json | OSIsoft PI Vision, PI Vision 2017 R2 and PI Vision 2017 R2 SP1. The affected product is vulnerable to cross-site scripting, w... | 4.8 - MEDIUM | 2020-01-15 | 2020-01-23 |
| CVE-2019-18271 json | OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to a cross-site request forger... | 8.8 - HIGH | 2020-01-15 | 2020-01-23 |
| CVE-2019-18244 json | In OSIsoft PI System multiple products and versions, a local attacker could view sensitive information in log files when serv... | 4.7 - MEDIUM | 2020-01-15 | 2020-07-25 |
| CVE-2019-13516 json | In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forgery pr... | 8.8 - HIGH | 2019-08-15 | 2023-03-08 |
| CVE-2019-13515 json | OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information. | 6.5 - MEDIUM | 2019-08-15 | 2019-10-09 |
| CVE-2018-19006 json | OSIsoft PI Vision, versions PI Vision 2017, and PI Vision 2017 R2, The application contains a cross-site scripting vulnerabil... | 4.8 - MEDIUM | 2019-04-08 | 2019-10-09 |
Known software with vulnerabilities from Osisoft
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Osisoft | Pi Api | 1.6.8.26 |
| Application | Osisoft | Pi Buffer Subsystem | 4.8.0.18 |
| Application | Osisoft | Pi Connector | 1.0.0.54 |
| Application | Osisoft | Pi Connector Relay | 2.5.19.0 |
| Application | Osisoft | Pi Data Archive | 2018 |
| Application | Osisoft | Pi Data Collection Manager | 2.5.19.0 |
| Application | Osisoft | Pi Integrator | 2.2.0.183 |
| Application | Osisoft | Pi Interface | 1.0.1.3 |
| Application | Osisoft | Pi Interface Configuration Utility | 1.5.0.7 |
| Application | Osisoft | Pi Opc Da Interface | 2.3.16.16 |
| Application | Osisoft | Pi To Ocs | 1.1.36.0 |
| Application | Osisoft | Pi Vision | 2017 |
| Application | Osisoft | Pi Web Api | 2014 |