First published: Fri May 25 2018(Updated: )
PI Coresight 2016 R2 contains a cross-site request forgery vulnerability that may allow access to the PI system. OSIsoft recommends that users upgrade to PI Vision 2017 or greater to mitigate this vulnerability.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
OSIsoft PI Coresight | <=2016-r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID of this vulnerability is CVE-2017-9641.
The severity of CVE-2017-9641 is high with a severity value of 8.8.
The affected software is PI Coresight 2016 R2.
To mitigate this vulnerability, it is recommended to upgrade to PI Vision 2017 or a later version.
You can find more information about CVE-2017-9641 in the following references: [SecurityFocus](http://www.securityfocus.com/bid/99540), [ICS-CERT advisory](https://ics-cert.us-cert.gov/advisories/ICSA-17-192-04), [OSIsoft TechSupport](https://techsupport.osisoft.com/Troubleshooting/Alerts/AL00320).