Protection Mechanism Failure in OSIsoft PI Web API - CVE-2019-13516
Published: August 29, 2019
Vulnerability identifier: #VU20455
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13516
CWE-ID: CWE-693
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to bypass certain restrictions.
The vulnerability exists due to the cross-site request forgery protection setting that has not taken effect. A local authenticated attacker can bypass certain security restrictions on the target system.
Affected software
OSIsoft PI Web API
Amazon Linux AMI
Gentoo Linux
Opensuse
Amazon Linux AMI
Gentoo Linux
Opensuse
How to mitigate CVE-2019-13516
Install updates from vendor's website.
OSIsoft PI Web API - update to 2018 SP1