SCADA Vulnerabilities & Exposures (SVE)

CRITIFENCE® SCADA Vulnerabilities and Exposures Database (SVE)

[SVE-794281765] OSIsoft PI Data Archive

Date Type Platform Author EDB-ID CVE-ID OSVDB-ID Download App SIS Signature
2018-03-13OtherOSIsoftOSIsoft self reported these vulnerabilities to NCCIC.N/ACVE-2018-7529 CVE-2018-7533 CVE-2018-7531 N/AN/AN/A

Source

						
							
								
#
# OSIsoft PI Data Archive
#


### VULNERABLE VENDOR
OSIsoft


### VULNERABLE PRODUCT
PI Data Archive 


### RESEARCHER
OSIsoft self reported these vulnerabilities to NCCIC.


### AFFECTED PRODUCTS
The following versions of PI Data Archive, a data storage solution, are affected:

PI Data Archive versions 2017 and prior


### IMPACT
Successful exploitation of these vulnerabilities could cause loss of network access to the device or allow escalated privileges that may result in gaining full control of the PI Data Archive server.


### VULNERABILITY OVERVIEW
DESERIALIZATION OF UNTRUSTED DATA CWE-502
Unauthenticated users may modify deserialized data to send custom requests that crash the server.
CVE-2018-7529 has been assigned to this vulnerability.
A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)


INCORRECT DEFAULT PERMISSIONS CWE-276
Insecure default configuration may allow escalation of privileges that gives the actor full control over the system.
CVE-2018-7533 has been assigned to this vulnerability.
A CVSS v3 base score of 7.3 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)


IMPROPER INPUT VALIDATION CWE-20
Unauthenticated users may use unvalidated custom requests to crash the server.
CVE-2018-7531 has been assigned to this vulnerability.
A CVSS v3 base score of 5.9 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)





### BACKGROUND
Critical Infrastructure Sectors: Multiple Sectors
Countries/Areas Deployed: Worldwide
Company Headquarters Location: USA




### MITIGATION

OSIsoft recommends that customers upgrade to PI Data Archive 2017 R2.  Obtain the update from OSIsoft.

OSIsoft has released the following advisory:

https://techsupport.osisoft.com/Troubleshooting/Alerts/AL00339