CVE-2015-1013
OSIsoft PI AF <2.6-2.7 & PI SQL for AF 2.1.2.19 - Auth Bypass
Title source: llmDescription
OSIsoft PI AF 2.6 and 2.7 and PI SQL for AF 2.1.2.19 do not ensure that the PI SQL (AF) Trusted Users group lacks the Everyone account, which allows remote authenticated users to bypass intended command restrictions via SQL statements.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://techsupport.osisoft.com/Troubleshooting/Alerts/AL00280
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-15-132-01
Scores
EPSS
0.0129
EPSS Percentile
67.2%
Details
CWE
CWE-89
Status
published
Products (2)
osisoft/pi_server
2.6
osisoft/pi_sql_for_af
2.1.2.19
Published
May 26, 2015
Tracked Since
Feb 18, 2026