CVE-2017-7926: CSRF
Published Aug 25, 2017
·Updated
A Cross-Site Request Forgery issue was discovered in OSIsoft PI Web API versions prior to 2017 (1.9.0). The vulnerability allows cross-site request forgery (CSRF) attacks to occur when an otherwise-unauthorized cross-site request is sent from a browser the server has previously authenticated.
Affected Software
1 affected component
OSIsoft PI Web API=1.8
Event History
Aug 25, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-7926?
CVE-2017-7926 is classified as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How does CVE-2017-7926 affect OSIsoft PI Web API?
CVE-2017-7926 allows unauthorized cross-site requests to be executed on behalf of authenticated users.
3
Which versions of OSIsoft PI Web API are vulnerable to CVE-2017-7926?
CVE-2017-7926 affects OSIsoft PI Web API versions prior to 1.9.0.
4
How do I fix CVE-2017-7926?
To mitigate CVE-2017-7926, upgrade to OSIsoft PI Web API version 1.9.0 or later.
5
What type of attack is possible due to CVE-2017-7926?
CVE-2017-7926 enables Cross-Site Request Forgery (CSRF) attacks against users of the affected API.