#VU24313 Improper access control in PI Vision - CVE-2019-18275
Published: January 15, 2020
PI Vision
OSIsoft
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions, which may return unauthorized tag data when viewing analysis data reference attributes. A remote authenticated attacker can bypass implemented security restrictions and gain unauthorized access to sensitive information.