VulnerabilityModified
CVE-2018-7500
Privileges may be escalated, giving attackers access to the PI System via the service account.
CRITICAL 9.8EPSS 1.85%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.85%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Privileges may be escalated, giving attackers access to the PI System via the service account.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.85% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- osisoft/pi web api · osisoft/pi vision
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/103396Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-072-04Mitigation, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/103396Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-072-04Mitigation, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.