VYPR
Unrated severityNVD Advisory· Published Apr 18, 2022· Updated Apr 16, 2025

OSIsoft PI Vision Cross-site Scripting

CVE-2020-25163

Description

A remote attacker with write access to PI ProcessBook files could inject code that is imported into OSIsoft PI Vision 2020 versions prior to 3.5.0. Unauthorized information disclosure, modification, or deletion is also possible if a victim views or interacts with the infected display. This vulnerability affects PI System data and other data accessible with victim’s user permissions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An XSS vulnerability in OSIsoft PI Vision 2020 before 3.5.0 allows attackers with write access to PI ProcessBook files to inject code, leading to information disclosure, modification, or deletion.

Vulnerability

A remote attacker with write access to PI ProcessBook files can inject malicious code that is imported into PI Vision 2020 versions prior to 3.5.0. This is an improper neutralization of input during web page generation (Cross-Site Scripting, CWE-79) vulnerability. The injected code executes when a victim views or interacts with the infected display. The affected product is PI Vision 2020, all versions before 3.5.0 [1].

Exploitation

The attacker requires write access to PI ProcessBook files, which can be achieved remotely. The exploit involves injecting malicious script into a ProcessBook file that is subsequently imported into PI Vision. No user interaction beyond viewing the infected display is required for the payload to execute. The CVSS vector string (AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N) indicates high attack complexity and low privileges required [1].

Impact

Successful exploitation leads to unauthorized information disclosure, modification, or deletion of PI System data and other data accessible with the victim's user permissions. The attacker gains the ability to perform actions with the victim's privileges, potentially compromising confidentiality and integrity of sensitive data. The scope of the attack can extend to other parts of the system accessible to the victim [1].

Mitigation

OSIsoft released PI Vision 2020 Version 3.5.0, which resolves this vulnerability. Users should upgrade to version 3.5.0 or later. OSIsoft also provides recommended defensive measures and configuration settings on their customer portal (login required). CISA recommends users take defensive measures to minimize risk [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Osisoft/PI Visionllm-create2 versions
    <3.5.0+ 1 more
    • (no CPE)range: <3.5.0
    • (no CPE)range: unspecified

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.