CVE-2021-43549
18.11.2021, 15:15
A remote authenticated attacker with write access to a PI Server could trick a user into interacting with a PI Web API endpoint and redirect them to a malicious website. As a result, a victim may disclose sensitive information to the attacker or be provided with false information.
Vendor | Product | Version |
---|---|---|
osisoft | pi_web_api | 𝑥 ≤ 2019 |
𝑥
= Vulnerable software versions