VulnerabilityModified
CVE-2017-7934
An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017.
MEDIUM 5.9EPSS 2.15%
Does this matter?
Lower severity and a low EPSS score (2.15%). Track it; it rarely justifies an emergency change on its own.
Description
An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Network Manager using older protocol versions contains a flaw that could allow a malicious user to authenticate with a server and then cause PI Network Manager to behave in an undefined manner.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.15% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- osisoft/pi data archive
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/99059Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-164-02Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/99059Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-164-02Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.