CWE
284 437
Advisory Published
Updated

CVE-2016-8365

First published: Tue Oct 11 2016(Updated: )

OSIsoft PI System software (Applications using PI Asset Framework (AF) Client versions prior to PI AF Client 2016, Version 2.8.0; Applications using PI Software Development Kit (SDK) versions prior to PI SDK 2016, Version 1.4.6; PI Buffer Subsystem, versions prior to and including, Version 4.4; and PI Data Archive versions prior to PI Data Archive 2015, Version 3.4.395.64) operates between endpoints without a complete model of endpoint features potentially causing the product to perform actions based on this incomplete model, which could result in a denial of service. OSIsoft reports that in order to exploit the vulnerability an attacker would need to be locally connected to a server. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H)

Credit: ics-cert@hq.dhs.gov

Affected SoftwareAffected VersionHow to fix
Osisoft Pi Af Client<2.8.0
Osisoft Pi Buffer Subsystem<4.5.0
OSIsoft PI Data Archive<3.4.400.1162
Osisoft Pi Sdk<1.4.6

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2016-8365?

    The severity of CVE-2016-8365 is medium with a severity value of 5.5.

  • Which versions of PI Asset Framework (AF) Client are affected by CVE-2016-8365?

    Versions prior to PI AF Client 2016, Version 2.8.0 are affected by CVE-2016-8365.

  • Which versions of PI Software Development Kit (SDK) are affected by CVE-2016-8365?

    Versions prior to PI SDK 2016, Version 1.4.6 are affected by CVE-2016-8365.

  • Which versions of PI Buffer Subsystem are affected by CVE-2016-8365?

    Versions prior to and including, Version 4.5.0 of PI Buffer Subsystem are affected by CVE-2016-8365.

  • Which version of OSIsoft PI Data Archive is affected by CVE-2016-8365?

    OSIsoft PI Data Archive with version up to and excluding 3.4.400.1162 is affected by CVE-2016-8365.

  • Where can I find more information about CVE-2016-8365?

    You can find more information about CVE-2016-8365 on the following websites: [SecurityFocus](http://www.securityfocus.com/bid/94165), [ICS-CERT](https://ics-cert.us-cert.gov/advisories/ICS-VU-313-03), [OSIsoft TechSupport](https://techsupport.osisoft.com/Troubleshooting/Alerts/AL00308).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203