OSIsoft kayıtları
osisoft üreticisine ait 45 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-20 Improper Input Validation5
- CWE-532 Insertion of Sensitive Information into Log File3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-863 Incorrect Authorization3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
45 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2017-9653İstismar yok | An Improper Authorization issue was discovered in OSIsoft PI Integrator for Business Analytics before 2016 R2, PI Integrator for Microsoft Aosisoft · pi integrator for business analystics · CWE-863 | Kritik9,8 | — | %2,3 | 14 Ağu 2017 |
40Planlayın | CVE-2018-7500İstismar yok | A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior.osisoft · pi web api · CWE-264 | Kritik9,8 | — | %1,8 | 14 Mar 2018 |
36İzleyin | CVE-2020-12021İstismar yok | In OSIsoft PI Web API 2019 Patch 1 (1.12.0.6346) and all previous versions, the affected product is vulnerable to a cross-site scripting attosisoft · pi web api · CWE-79 | Kritik9,0 | — | %1,6 | 23 Haz 2020 |
35İzleyin | CVE-2012-3008İstismar yok | Stack-based buffer overflow in OSIsoft PI OPC DA Interface before 2.3.20.9 allows remote authenticated users to execute arbitrary code by seosisoft · pi opc da interface · CWE-119 | Yüksek8,5 | — | %4,7 | 20 Tem 2012 |
35İzleyin | CVE-2017-9641İstismar yok | PI Coresight 2016 R2 contains a cross-site request forgery vulnerability that may allow access to the PI system.osisoft · pi coresight · CWE-352 | Yüksek8,8 | — | %0,9 | 25 May 2018 |
35İzleyin | CVE-2017-7926İstismar yok | A Cross-Site Request Forgery issue was discovered in OSIsoft PI Web API versions prior to 2017 (1.9.0).osisoft · pi web api · CWE-352 | Yüksek8,8 | — | %0,8 | 25 Ağu 2017 |
35İzleyin | CVE-2019-13516İstismar yok | In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forgery protection settinosisoft · pi web api · CWE-693 | Yüksek8,8 | — | %0,7 | 15 Ağu 2019 |
35İzleyin | CVE-2019-18271İstismar yok | OSIsoft PI Vision, All versions of PI Vision prior to 2019.osisoft · pi vision · CWE-352 | Yüksek8,8 | — | %0,6 | 15 Oca 2020 |
31İzleyin | CVE-2020-10604İstismar yok | In OSIsoft PI System multiple products and versions, a remote, unauthenticated attacker could crash PI Network Manager service through speciosisoft · pi data archive · CWE-248 | Yüksek7,5 | — | %2,1 | 24 Tem 2020 |
31İzleyin | CVE-2018-7529İstismar yok | A Deserialization of Untrusted Data issue was discovered in OSIsoft PI Data Archive versions 2017 and prior.osisoft · pi data archive · CWE-502 | Yüksek7,5 | — | %2,1 | 14 Mar 2018 |
31İzleyin | CVE-2020-10610İstismar yok | In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PIosisoft · pi api · CWE-427 | Yüksek7,8 | — | %0,4 | 24 Tem 2020 |
31İzleyin | CVE-2017-5153İstismar yok | An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using the PI AF Services osisoft · pi coresight · CWE-532 | Yüksek7,8 | — | %0,4 | 13 Şub 2017 |
31İzleyin | CVE-2018-7533İstismar yok | An Incorrect Default Permissions issue was discovered in OSIsoft PI Data Archive versions 2017 and prior.osisoft · pi data archive · CWE-276 | Yüksek7,8 | — | %0,3 | 14 Mar 2018 |
31İzleyin | CVE-2020-10606İstismar yok | In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software.osisoft · pi api · CWE-276 | Yüksek7,8 | — | %0,3 | 24 Tem 2020 |
31İzleyin | CVE-2020-10608İstismar yok | In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI Syosisoft · pi api · CWE-347 | Yüksek7,8 | — | %0,2 | 24 Tem 2020 |
30İzleyin | CVE-2017-7930İstismar yok | An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017.osisoft · pi data archive · CWE-287 | Yüksek7,4 | — | %2,0 | 25 Ağu 2017 |
29İzleyin | CVE-2020-25163İstismar yok | OSIsoft PI Vision Cross-site Scriptingosisoft · pi vision · CWE-79 | Yüksek7,3 | — | %0,9 | 18 Nis 2022 |
28İzleyin | CVE-2013-2809İstismar yok | The DNP Master Driver in the OSIsoft PI Interface before 3.1.2.54 for DNP3 allows remote attackers to cause a denial of service (interface sosisoft · pi interface · CWE-20 | Yüksek7,1 | — | %1,5 | 12 Nis 2014 |
28İzleyin | CVE-2020-10600İstismar yok | An authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure.osisoft · pi data archive · CWE-476 | Yüksek7,1 | — | %0,8 | 24 Tem 2020 |
26İzleyin | CVE-2016-4530İstismar yok | OSIsoft PI SQL Data Access Server (aka OLE DB) 2016 1.5 allows remote authenticated users to cause a denial of service (service outage and dosisoft · pi sql data access server 2016 · CWE-20 | Orta6,5 | — | %1,4 | 19 Haz 2016 |
26İzleyin | CVE-2019-13515İstismar yok | OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information.osisoft · pi web api · CWE-532 | Orta6,5 | — | %1,3 | 15 Ağu 2019 |
26İzleyin | CVE-2015-1013İstismar yok | OSIsoft PI AF 2.6 and 2.7 and PI SQL for AF 2.1.2.19 do not ensure that the PI SQL (AF) Trusted Users group lacks the Everyone account, whicosisoft · pi server · CWE-89 | Orta6,5 | — | %1,3 | 25 May 2015 |
26İzleyin | CVE-2016-4518İstismar yok | OSIsoft PI AF Server before 2016 2.8.0 allows remote authenticated users to cause a denial of service (service outage) via a message.osisoft · pi af server 2016 · CWE-20 | Orta6,5 | — | %1,2 | 19 Haz 2016 |
26İzleyin | CVE-2019-18275İstismar yok | OSIsoft PI Vision, All versions of PI Vision prior to 2019.osisoft · pi vision · CWE-284 | Orta6,5 | — | %1,1 | 15 Oca 2020 |
26İzleyin | CVE-2020-25167İstismar yok | OSIsoft PI Vision Incorrect Authorizationosisoft · pi vision · CWE-863 | Orta6,5 | — | %0,7 | 18 Nis 2022 |
- CVE-2017-965340Planlayın
An Improper Authorization issue was discovered in OSIsoft PI Integrator for Business Analytics before 2016 R2, PI Integrator for Microsoft A
KritikCVSS 9,8İstismar yokEPSS %2osisoft · pi integrator for business analystics14 Ağu 2017
- CVE-2018-750040Planlayın
A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior.
KritikCVSS 9,8İstismar yokEPSS %2osisoft · pi web api14 Mar 2018
- CVE-2020-1202136İzleyin
In OSIsoft PI Web API 2019 Patch 1 (1.12.0.6346) and all previous versions, the affected product is vulnerable to a cross-site scripting att
KritikCVSS 9,0İstismar yokEPSS %2osisoft · pi web api23 Haz 2020
- CVE-2012-300835İzleyin
Stack-based buffer overflow in OSIsoft PI OPC DA Interface before 2.3.20.9 allows remote authenticated users to execute arbitrary code by se
YüksekCVSS 8,5İstismar yokEPSS %5osisoft · pi opc da interface20 Tem 2012
- CVE-2017-964135İzleyin
PI Coresight 2016 R2 contains a cross-site request forgery vulnerability that may allow access to the PI system.
YüksekCVSS 8,8İstismar yokEPSS %1osisoft · pi coresight25 May 2018
- CVE-2017-792635İzleyin
A Cross-Site Request Forgery issue was discovered in OSIsoft PI Web API versions prior to 2017 (1.9.0).
YüksekCVSS 8,8İstismar yokEPSS %1osisoft · pi web api25 Ağu 2017
- CVE-2019-1351635İzleyin
In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forgery protection settin
YüksekCVSS 8,8İstismar yokEPSS %1osisoft · pi web api15 Ağu 2019
- CVE-2019-1827135İzleyin
OSIsoft PI Vision, All versions of PI Vision prior to 2019.
YüksekCVSS 8,8İstismar yokEPSS %1osisoft · pi vision15 Oca 2020
- CVE-2020-1060431İzleyin
In OSIsoft PI System multiple products and versions, a remote, unauthenticated attacker could crash PI Network Manager service through speci
YüksekCVSS 7,5İstismar yokEPSS %2osisoft · pi data archive24 Tem 2020
- CVE-2018-752931İzleyin
A Deserialization of Untrusted Data issue was discovered in OSIsoft PI Data Archive versions 2017 and prior.
YüksekCVSS 7,5İstismar yokEPSS %2osisoft · pi data archive14 Mar 2018
- CVE-2020-1061031İzleyin
In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI
YüksekCVSS 7,8İstismar yokEPSS %0osisoft · pi api24 Tem 2020
- CVE-2017-515331İzleyin
An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using the PI AF Services
YüksekCVSS 7,8İstismar yokEPSS %0osisoft · pi coresight13 Şub 2017
- CVE-2018-753331İzleyin
An Incorrect Default Permissions issue was discovered in OSIsoft PI Data Archive versions 2017 and prior.
YüksekCVSS 7,8İstismar yokEPSS %0osisoft · pi data archive14 Mar 2018
- CVE-2020-1060631İzleyin
In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software.
YüksekCVSS 7,8İstismar yokEPSS %0osisoft · pi api24 Tem 2020
- CVE-2020-1060831İzleyin
In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI Sy
YüksekCVSS 7,8İstismar yokEPSS %0osisoft · pi api24 Tem 2020
- CVE-2017-793030İzleyin
An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017.
YüksekCVSS 7,4İstismar yokEPSS %2osisoft · pi data archive25 Ağu 2017
- CVE-2020-2516329İzleyin
OSIsoft PI Vision Cross-site Scripting
YüksekCVSS 7,3İstismar yokEPSS %1osisoft · pi vision18 Nis 2022
- CVE-2013-280928İzleyin
The DNP Master Driver in the OSIsoft PI Interface before 3.1.2.54 for DNP3 allows remote attackers to cause a denial of service (interface s
YüksekCVSS 7,1İstismar yokEPSS %1osisoft · pi interface12 Nis 2014
- CVE-2020-1060028İzleyin
An authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure.
YüksekCVSS 7,1İstismar yokEPSS %1osisoft · pi data archive24 Tem 2020
- CVE-2016-453026İzleyin
OSIsoft PI SQL Data Access Server (aka OLE DB) 2016 1.5 allows remote authenticated users to cause a denial of service (service outage and d
OrtaCVSS 6,5İstismar yokEPSS %1osisoft · pi sql data access server 201619 Haz 2016
- CVE-2019-1351526İzleyin
OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information.
OrtaCVSS 6,5İstismar yokEPSS %1osisoft · pi web api15 Ağu 2019
- CVE-2015-101326İzleyin
OSIsoft PI AF 2.6 and 2.7 and PI SQL for AF 2.1.2.19 do not ensure that the PI SQL (AF) Trusted Users group lacks the Everyone account, whic
OrtaCVSS 6,5İstismar yokEPSS %1osisoft · pi server25 May 2015
- CVE-2016-451826İzleyin
OSIsoft PI AF Server before 2016 2.8.0 allows remote authenticated users to cause a denial of service (service outage) via a message.
OrtaCVSS 6,5İstismar yokEPSS %1osisoft · pi af server 201619 Haz 2016
- CVE-2019-1827526İzleyin
OSIsoft PI Vision, All versions of PI Vision prior to 2019.
OrtaCVSS 6,5İstismar yokEPSS %1osisoft · pi vision15 Oca 2020
- CVE-2020-2516726İzleyin
OSIsoft PI Vision Incorrect Authorization
OrtaCVSS 6,5İstismar yokEPSS %1osisoft · pi vision18 Nis 2022