VYPR

Pi Server

by Osisoft

CVEs (4)

  • CVE-2021-43549MedNov 18, 2021
    risk 0.45cvss 6.9epss 0.01

    A remote authenticated attacker with write access to a PI Server could trick a user into interacting with a PI Web API endpoint and redirect them to a malicious website. As a result, a victim may disclose sensitive information to the attacker or be provided with false…

  • CVE-2016-4518MedJun 19, 2016
    risk 0.42cvss 6.5epss 0.01

    OSIsoft PI AF Server before 2016 2.8.0 allows remote authenticated users to cause a denial of service (service outage) via a message.

  • CVE-2015-1013May 26, 2015
    risk 0.00cvss epss 0.01

    OSIsoft PI AF 2.6 and 2.7 and PI SQL for AF 2.1.2.19 do not ensure that the PI SQL (AF) Trusted Users group lacks the Everyone account, which allows remote authenticated users to bypass intended command restrictions via SQL statements.

  • CVE-2009-0209Oct 1, 2009
    risk 0.00cvss epss 0.01

    PI Server in OSIsoft PI System before 3.4.380.x does not properly use encryption in the default authentication process, which allows remote attackers to read or modify information in databases via unspecified vectors.