CVE-2017-7930: High severity osisoft pi data archive vulnerability
An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Data Archive has protocol flaws with the potential to expose change records in the clear and allow a malicious party to spoof a server within a collective.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7930?
CVE-2017-7930 has a severity rating of medium due to its improper authentication issue that can lead to exposure of sensitive data.
How do I fix CVE-2017-7930?
To fix CVE-2017-7930, upgrade your OSIsoft PI Data Archive to version 3.4.410.1256 or later.
What are the potential impacts of CVE-2017-7930?
The potential impacts of CVE-2017-7930 include unauthorized access to change records and server spoofing within a collective.
Which versions of OSIsoft PI Data Archive are affected by CVE-2017-7930?
CVE-2017-7930 affects OSIsoft PI Data Archive versions prior to 3.4.410.1256.
Is there a workaround for CVE-2017-7930 while waiting for a patch?
Currently, there are no documented workarounds for CVE-2017-7930, so upgrading to a fixed version is recommended.