A remote attacker with write access to PI ProcessBook files could inject code that is imported into OSIsoft PI Vision 2020 versions prior to 3.5.0. Unauthorized information disclosure, modification, or deletion is also possible if a victim views or interacts with the infected display. This vulnerability affects PI System data and other data accessible with victim’s user permissions.
References
Link | Resource |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-20-315-02 | Third Party Advisory US Government Resource |
Configurations
Information
Published : 2022-04-18 10:15
Updated : 2022-04-26 20:21
NVD link : CVE-2020-25163
Mitre link : CVE-2020-25163
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
osisoft
- pi_vision