Lucene search

K
cveCertccCVE-2009-0209
HistoryOct 01, 2009 - 3:30 p.m.

CVE-2009-0209

2009-10-0115:30:00
CWE-310
certcc
web.nvd.nist.gov
26
cve-2009-0209
pi server
osisoft
pi system
encryption
authentication
remote attackers
databases
nvd

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

6.6

Confidence

Low

EPSS

0.002

Percentile

56.3%

PI Server in OSIsoft PI System before 3.4.380.x does not properly use encryption in the default authentication process, which allows remote attackers to read or modify information in databases via unspecified vectors.

Affected configurations

Nvd
Node
osisoftpi_serverRange3.4.375.99sp232bit_windows
OR
osisoftpi_serverMatch2.4
OR
osisoftpi_serverMatch2.6
OR
osisoftpi_serverMatch3.4.363.97
OR
osisoftpi_serverMatch3.4.370
OR
osisoftpi_serverMatch3.4.375.99sp264bit_windows
VendorProductVersionCPE
osisoftpi_server*cpe:2.3:a:osisoft:pi_server:*:sp2:32bit_windows:*:*:*:*:*
osisoftpi_server2.4cpe:2.3:a:osisoft:pi_server:2.4:*:*:*:*:*:*:*
osisoftpi_server2.6cpe:2.3:a:osisoft:pi_server:2.6:*:*:*:*:*:*:*
osisoftpi_server3.4.363.97cpe:2.3:a:osisoft:pi_server:3.4.363.97:*:*:*:*:*:*:*
osisoftpi_server3.4.370cpe:2.3:a:osisoft:pi_server:3.4.370:*:*:*:*:*:*:*
osisoftpi_server3.4.375.99cpe:2.3:a:osisoft:pi_server:3.4.375.99:sp2:64bit_windows:*:*:*:*:*

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

6.6

Confidence

Low

EPSS

0.002

Percentile

56.3%

Related for CVE-2009-0209