ICSA-20-133-02: Osisoft pi asset framework (af) client vulnerability
Affected Software
18 affected components
OSIsoft Applications using PI Asset Framework (AF) Client versions prior to and including PI AF Client 2018 SP3 Patch 1, Version 2.10.7.283
OSIsoft Applications using PI Software Development Kit (SDK) versions prior to and including PI SDK 2018 SP1, Version 1.4.7.602
OSIsoft PI API for Windows Integrated Security versions prior to and including 2.0.2.5,
OSIsoft PI API versions prior to and including 1.6.8.26
OSIsoft PI Buffer Subsystem versions prior to and including 4.8.0.18
OSIsoft PI Connector for BACnet, versions prior to and including 1.2.0.6
OSIsoft PI Connector for CygNet, versions prior to and including 1.4.0.17
OSIsoft PI Connector for DC Systems RTscada, versions prior to and including 1.2.0.42
OSIsoft PI Connector for Ethernet/IP, versions prior to and including 1.1.0.10
OSIsoft PI Connector for HART-IP, versions prior to and including 1.3.0.1
OSIsoft PI Connector for Ping, versions prior to and including 1.0.0.54
OSIsoft PI Connector for Wonderware Historian, versions prior to and including 1.5.0.88
OSIsoft PI Connector Relay, versions prior to and including 2.5.19.0
OSIsoft PI Data Archive versions prior to and including PI Data Archive 2018 SP3, Version 3.4.430.460
OSIsoft PI Data Collection Manager, versions prior to and including 2.5.19.0
OSIsoft PI Integrator for Business Analytics versions prior to and including 2018 R2 SP1, Version 2.2.0.183
OSIsoft PI Interface Configuration Utility (ICU) versions prior to and including 1.5.0.7
OSIsoft PI to OCS versions prior to and including 1.1.36.0
Event History
Feb 23, 2025
Advisory Published
05:14 PM
Frequently Asked Questions
1
What is the severity of ICSA-20-133-02?
The severity of ICSA-20-133-02 is considered critical due to the potential for unauthenticated remote code execution.
2
How do I fix ICSA-20-133-02?
To fix ICSA-20-133-02, update affected OSIsoft applications to the latest version or apply the recommended patches.
3
What systems are affected by ICSA-20-133-02?
ICSA-20-133-02 affects various OSIsoft applications including PI Asset Framework, PI SDK, and PI API among others.
4
What are the potential impacts of ICSA-20-133-02?
The potential impacts of ICSA-20-133-02 include unauthorized access, data manipulation, and remote code execution.
5
Is there a workaround for ICSA-20-133-02?
There are no recommended workarounds for ICSA-20-133-02, and the best course of action is to apply the proper updates.