CVE Vulnerabilities

CVE-2018-7500

Published: Mar 14, 2018 | Modified: Oct 09, 2019
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Privileges may be escalated, giving attackers access to the PI System via the service account.

Affected Software

Name Vendor Start Version End Version
Pi_web_api Osisoft * 2017 (including)
Pi_web_api Osisoft 2017-r2 (including) 2017-r2 (including)

References