First published: Mon Apr 18 2022(Updated: )
OSIsoft PI Vision 2020 versions prior to 3.5.0 could disclose information to a user with insufficient privileges for an AF attribute.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
OSIsoft PI Vision | <3.5.0 | |
OSIsoft CRITICAL INFRASTRUCTURE SECTORS: Multiple | ||
OSIsoft COUNTRIES/AREAS DEPLOYED: Worldwide | ||
OSIsoft COMPANY HEADQUARTERS LOCATION: United States |
OSIsoft released PI Vision 2020 Version 3.5.0, which resolves these vulnerabilities. Recommended defensive measures and related configuration settings are described on the OSIsoft customer portal (Login required).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-25167.
The title of this vulnerability is "OSIsoft PI Vision 2020 versions prior to 3.5.0 could disclose information to a user with insufficient privileges for an AF attribute."
The severity rating of CVE-2020-25167 is medium with a score of 6.5.
OSIsoft PI Vision 2020 versions prior to 3.5.0 are affected by this vulnerability.
To fix this vulnerability, update OSIsoft PI Vision to version 3.5.0 or later.