PT-2022-8705 · Osisoft · Osisoft Pi Vision+1

Published

2022-04-18

·

Updated

2022-04-27

·

CVE-2020-25163

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OSIsoft PI Vision 2020 versions prior to 3.5.0
Description A remote attacker with write access to PI ProcessBook files could inject code that is imported into OSIsoft PI Vision. Unauthorized information disclosure, modification, or deletion is also possible if a victim views or interacts with the infected display. This issue affects PI System data and other data accessible with the victim's user permissions.
Recommendations For versions prior to 3.5.0, update to version 3.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to PI ProcessBook files to prevent unauthorized code injection. Avoid interacting with potentially infected displays until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25163

Affected Products

Osisoft Pi Vision
Pi Processbook