First published: Tue Nov 09 2021(Updated: )
A remote authenticated attacker with write access to a PI Server could trick a user into interacting with a PI Web API endpoint and redirect them to a malicious website. As a result, a victim may disclose sensitive information to the attacker or be provided with false information.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
OSIsoft PI Web API | ||
OSIsoft PI API | <=2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43549 has been classified as a medium severity vulnerability.
To mitigate CVE-2021-43549, ensure that appropriate access controls are enforced and users are educated to avoid interacting with untrusted links.
CVE-2021-43549 affects all versions of PI Web API 2019 SPI and prior, which are managed by OSIsoft.
CVE-2021-43549 allows attackers to trick users into revealing sensitive information or providing false information via malicious redirects.
At this time, there is no public information indicating that exploit code for CVE-2021-43549 is readily available.