CVE-2020-25163: OSIsoft PI Vision Cross-site Scripting
A remote attacker with write access to PI ProcessBook files could inject code that is imported into OSIsoft PI Vision 2020 versions prior to 3.5.0. Unauthorized information disclosure, modification, or deletion is also possible if a victim views or interacts with the infected display. This vulnerability affects PI System data and other data accessible with victim’s user permissions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-25163?
CVE-2020-25163 is a vulnerability that allows a remote attacker with write access to PI ProcessBook files to inject code into OSIsoft PI Vision 2020 versions prior to 3.5.0.
How does CVE-2020-25163 impact OSIsoft PI Vision 2020?
CVE-2020-25163 allows unauthorized information disclosure, modification, or deletion if a victim views or interacts with an infected display in OSIsoft PI Vision 2020.
What is the severity of CVE-2020-25163?
CVE-2020-25163 has a severity rating of 7.3, which is considered high.
How can an attacker exploit CVE-2020-25163?
An attacker with write access to PI ProcessBook files can inject malicious code, which is then imported into OSIsoft PI Vision displays.
Is there a fix available for CVE-2020-25163?
Yes, a fix for CVE-2020-25163 is available in OSIsoft PI Vision version 3.5.0 and later.