CVE-2009-0209: Medium severity OSIsoft PI Server vulnerability
PI Server in OSIsoft PI System before 3.4.380.x does not properly use encryption in the default authentication process, which allows remote attackers to read or modify information in databases via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0209?
CVE-2009-0209 is considered to have a moderate severity level due to the potential for unauthorized access to databases.
How do I fix CVE-2009-0209?
To fix CVE-2009-0209, it is recommended to upgrade to the latest version of the OSIsoft PI Server that addresses encryption issues in authentication.
What versions of OSIsoft PI Server are affected by CVE-2009-0209?
CVE-2009-0209 affects several versions of OSIsoft PI Server prior to 3.4.380.x, including versions 2.4, 2.6, 3.4.363.97, and 3.4.375.99.
What types of attacks can CVE-2009-0209 facilitate?
CVE-2009-0209 can facilitate attacks that allow remote attackers to read or modify information in databases due to insufficient encryption.
Is there any workaround for CVE-2009-0209?
There are no recommended workarounds for CVE-2009-0209; the best course of action is to upgrade to a secure version.