Improper authentication in PI Data Archive - CVE-2017-7934
Published: June 15, 2017
Vulnerability identifier: #VU7100
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7934
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to the system.
The weakness exists due to a flaw in PI Network Manager using older protocol versions. A remote attacker can authenticate with a server and then cause PI Network Manager to behave in an undefined manner.
Successful exploitation results may result in denial of service
The weakness exists due to a flaw in PI Network Manager using older protocol versions. A remote attacker can authenticate with a server and then cause PI Network Manager to behave in an undefined manner.
Successful exploitation results may result in denial of service
Affected software
PI Data Archive
How to mitigate CVE-2017-7934
Update to version 2017.