VYPR
Unrated severityNVD Advisory· Published Nov 17, 2021· Updated Sep 16, 2024

OSIsoft PI Vision

CVE-2021-43553

Description

PI Vision could disclose information to a user with insufficient privileges for an AF attribute that is the child of another attribute and is configured as a Limits property.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

PI Vision prior to 2021 incorrectly authorizes access to child AF attributes configured as Limits, allowing information disclosure to low-privileged users.

Vulnerability

PI Vision versions prior to 2021 contain an incorrect authorization vulnerability (CWE-863) in the handling of AF attributes that are children of another attribute and configured as a Limits property. This flaw allows users with insufficient privileges to view the attribute's data, bypassing intended access controls [1].

Exploitation

An attacker with low-privileged access (e.g., a user with insufficient permissions for the parent attribute) can remotely exploit this vulnerability by interacting with the PI Vision web interface. The attack complexity is high, requiring specific conditions where a child attribute is configured as a Limits property and the user lacks the necessary privileges for that attribute [1].

Impact

Successful exploitation results in unauthorized information disclosure of AF attribute data. The confidentiality impact is limited to the data exposed, with no modification or deletion capabilities. The scope is unchanged, and the attacker gains access to restricted information that should be protected by authorization controls [1].

Mitigation

OSIsoft recommends upgrading to PI Vision 2021, which contains the fix. Workarounds include configuring Publisher and Explorer roles in PI Vision User Access Levels to restrict access. No other mitigations are provided in the available references [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.