VULNERABILITY INTELLIGENCE
CVE-2017-9641
CVSS score8.8 HIGH
EPSS probability0.85%
CISA KEVNot currently listed
Published2018-05-25
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
PI Coresight 2016 R2 contains a cross-site request forgery vulnerability that may allow access to the PI system. OSIsoft recommends that users upgrade to PI Vision 2017 or greater to mitigate this vulnerability.
Weakness classification
- CWE-352: Cross-Site Request Forgery (CSRF)
Primary references
- ics-cert@hq.dhs.gov — Third Party Advisory, VDB Entry
- ics-cert@hq.dhs.gov — Third Party Advisory, US Government Resource
- ics-cert@hq.dhs.gov — Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory, US Government Resource
- af854a3a-2127-422b-91ae-364da2661108 — Vendor Advisory