VulnerabilityModified
CVE-2015-1013
OSIsoft PI AF 2.6 and 2.7 and PI SQL for AF 2.1.2.19 do not ensure that the PI SQL (AF) Trusted Users group lacks the Everyone account, which allows remote authenticated users to bypass intended command restrictions via SQL statements.
MEDIUM 6.5EPSS 1.26%
Does this matter?
Lower severity and a low EPSS score (1.26%). Track it; it rarely justifies an emergency change on its own.
Description
OSIsoft PI AF 2.6 and 2.7 and PI SQL for AF 2.1.2.19 do not ensure that the PI SQL (AF) Trusted Users group lacks the Everyone account, which allows remote authenticated users to bypass intended command restrictions via SQL statements.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.26% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- osisoft/pi server · osisoft/pi sql for af
- Source
- ics-cert@hq.dhs.gov
References
- https://ics-cert.us-cert.gov/advisories/ICSA-15-132-01Third Party Advisory, US Government Resource
- https://techsupport.osisoft.com/Troubleshooting/Alerts/AL00280Vendor Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-15-132-01Third Party Advisory, US Government Resource
- https://techsupport.osisoft.com/Troubleshooting/Alerts/AL00280Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.