CVE-2015-1013

OSIsoft PI AF <2.6-2.7 & PI SQL for AF 2.1.2.19 - Auth Bypass

Title source: llm
STIX 2.1

Description

OSIsoft PI AF 2.6 and 2.7 and PI SQL for AF 2.1.2.19 do not ensure that the PI SQL (AF) Trusted Users group lacks the Everyone account, which allows remote authenticated users to bypass intended command restrictions via SQL statements.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-15-132-01

Scores

EPSS 0.0129
EPSS Percentile 67.2%

Details

CWE
CWE-89
Status published
Products (2)
osisoft/pi_server 2.6
osisoft/pi_sql_for_af 2.1.2.19
Published May 26, 2015
Tracked Since Feb 18, 2026