A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Privileges may be escalated, giving attackers access to the PI System via the service account.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/103396 | vdb entry third party advisory |
https://ics-cert.us-cert.gov/advisories/ICSA-18-072-04 | us government resource third party advisory mitigation |