CVE-2017-9653

CRITICAL

OSIsoft PI Integrator <2016 R2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An Improper Authorization issue was discovered in OSIsoft PI Integrator for Business Analytics before 2016 R2, PI Integrator for Microsoft Azure before 2016 R2 SP1, and PI Integrator for SAP HANA before 2017. An attacker is able to gain privileged access to the system while unauthorized.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/100212
Mitigation, Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-17-220-01

Scores

CVSS v3 9.8
EPSS 0.0234
EPSS Percentile 81.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-863
Status published
Products (3)
osisoft/pi_integrator_for_business_analystics 2016
osisoft/pi_integrator_for_microsoft_azure 2016
osisoft/pi_integrator_for_sap_hana 2016
Published Aug 14, 2017
Tracked Since Feb 18, 2026