Lucene search

K
nvd[email protected]NVD:CVE-2015-1013
HistoryMay 26, 2015 - 1:59 a.m.

CVE-2015-1013

2015-05-2601:59:01
CWE-89
web.nvd.nist.gov
3

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

64.4%

OSIsoft PI AF 2.6 and 2.7 and PI SQL for AF 2.1.2.19 do not ensure that the PI SQL (AF) Trusted Users group lacks the Everyone account, which allows remote authenticated users to bypass intended command restrictions via SQL statements.

Affected configurations

Nvd
Node
osisoftpi_serverMatch2.6
OR
osisoftpi_sql_for_afMatch2.1.2.19
VendorProductVersionCPE
osisoftpi_server2.6cpe:2.3:a:osisoft:pi_server:2.6:*:*:*:*:*:*:*
osisoftpi_sql_for_af2.1.2.19cpe:2.3:a:osisoft:pi_sql_for_af:2.1.2.19:*:*:*:*:*:*:*

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

64.4%

Related for NVD:CVE-2015-1013