An Incorrect Default Permissions issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Insecure default configuration may allow escalation of privileges that gives the actor full control over the system.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-18-072-02 | third party advisory us government resource |
http://www.securityfocus.com/bid/103399 | vdb entry third party advisory |