First published: Wed Jan 15 2020(Updated: )
OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to a cross-site request forgery that may be introduced on the PI Vision administration site.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
OSIsoft | <2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18271 has been assigned a medium severity rating due to the potential for cross-site request forgery.
To mitigate CVE-2019-18271, upgrade to a version of OSIsoft PI Vision released after 2019.
CVE-2019-18271 affects all versions of OSIsoft PI Vision prior to 2019.
CVE-2019-18271 is classified as a cross-site request forgery (CSRF) vulnerability.
An attacker could exploit CVE-2019-18271 to perform actions on the PI Vision administration site without user consent.