CVE-2020-25163
OSIsoft PI Vision Cross-site Scripting
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 7.7EPSS 0.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
18 abr 2022Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
A remote attacker with write access to PI ProcessBook files could inject code that is imported into OSIsoft PI Vision 2020 versions prior to 3.5.0. Unauthorized information disclosure, modification, or deletion is also possible if a victim views or interacts with the infected display. This vulnerability affects PI System data and other data accessible with victim’s user permissions.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Produtos afetados
OSIsoft · PI VisionQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →