PT-2018-18138 · Osisoft · Osisoft Pi Data Archive

Published

2018-03-14

·

Updated

2019-10-09

·

CVE-2018-7533

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OSIsoft PI Data Archive versions 2017 and prior
Description An issue with incorrect default permissions was found, which may allow an actor to escalate privileges and gain full control over the system due to an insecure default configuration.
Recommendations For OSIsoft PI Data Archive versions 2017 and prior, update the configuration to secure default permissions to prevent privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-7533

Affected Products

Osisoft Pi Data Archive