OSIsoft LLC Update
3053Warning Date
Severity Level
Warning Number
Target Sector
16 January, 2020
● High
2020-808
All
Description:
OSIsoft LLC has released security update to address multiple vulnerabilities in the following product:
- PI Vision prior to and including 2019
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Cross-site request forgery (CSRF).
- Cross-site scripting (XSS) attack.
- Improper access control.
- Inclusion of sensitive information in log files.
Best practice and Recommendations:
The CERT team encourages users to review OSIsoft LLC security advisory and apply the necessary updates:
https://customers.osisoft.com/s/knowledgearticle?knowledgeArticleUrl=000024732