CVE-2019-18244: Medium severity osisoft pi asset framework (af) client vulnerability
In OSIsoft PI System multiple products and versions, a local attacker could view sensitive information in log files when service accounts are customized during installation or upgrade of PI Vision. The update fixes a previously reported issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-18244?
CVE-2019-18244 has been classified as a moderate severity vulnerability.
How do I fix CVE-2019-18244?
To fix CVE-2019-18244, update the affected OSIsoft products to the latest version provided by the vendor.
What products are affected by CVE-2019-18244?
CVE-2019-18244 affects multiple versions of OSIsoft PI Vision and several applications using PI SDK, PI API, and various PI Connectors.
Can CVE-2019-18244 be exploited remotely?
CVE-2019-18244 requires local access to the system, as it is related to sensitive information in log files.
What type of information can be exposed by CVE-2019-18244?
CVE-2019-18244 can expose sensitive information stored in log files due to improper handling of service accounts during installation or upgrade.