Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Osisoft

First CVE: Oct 1, 2009Active for: 17 yearsTotal CVEs: 45
20.2
VTI Score
Low

OSIsoft develops a focused but widely deployed suite of industrial data infrastructure software, with its vulnerability footprint concentrated in products such as PI Vision, PI Data Archive, PI Web API, and related components that serve as central repositories and interfaces for operational-technology environments. The exposure recurs through application-layer weakness classes including cross-site scripting, improper input validation, cross-site request forgery, authorization flaws, and sensitive-information leakage in logs—patterns typical of web-facing systems managing access to industrial datasets. A meaningful share of the vendor's vulnerabilities reach serious severity, reflecting the operational criticality of these products in manufacturing, utilities, and other process-heavy industries. Defenders should treat OSIsoft advisories as high-priority for any deployment in production environments and implement network segmentation and access controls around these data-tier systems; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
45
Total CVEs
More Total CVEs than 98% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Osisoft over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 1, 2009
16 years ago
Most Recent CVE
Apr 18, 2022
1,558 days ago

Products(24 total)

Top CVEs

Signals from CVEs in this vendor scope (45 CVEs).

45 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-7500CRITICAL
A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Privileges may be escalated, giving attackers access to the PI
Mar 14, 20189.831NONO
CVE-2017-9653CRITICAL
An Improper Authorization issue was discovered in OSIsoft PI Integrator for Business Analytics before 2016 R2, PI Integrator for Microsoft Azure before 2016 R2 SP1, and PI Integrat
Aug 14, 20179.831NONO
CVE-2012-3008HIGH
Stack-based buffer overflow in OSIsoft PI OPC DA Interface before 2.3.20.9 allows remote authenticated users to execute arbitrary code by sending packet data during the processing
Jul 20, 20128.528NONO
CVE-2019-13516HIGH
In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forgery protection setting that has not taken effect.
Aug 15, 20198.827NONO
CVE-2017-7926HIGH
A Cross-Site Request Forgery issue was discovered in OSIsoft PI Web API versions prior to 2017 (1.9.0). The vulnerability allows cross-site request forgery (CSRF) attacks to occur
Aug 25, 20178.827NONO
CVE-2020-10608HIGH
In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can ta
Jul 24, 20207.826NONO
CVE-2020-10604HIGH
In OSIsoft PI System multiple products and versions, a remote, unauthenticated attacker could crash PI Network Manager service through specially crafted requests. This can result i
Jul 25, 20207.525NONO
CVE-2017-9641HIGH
PI Coresight 2016 R2 contains a cross-site request forgery vulnerability that may allow access to the PI system. OSIsoft recommends that users upgrade to PI Vision 2017 or greater
May 25, 20188.825NONO
CVE-2017-5153HIGH
An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using the PI AF Services 2016 R2 integrated install kit. An infor
Feb 13, 20177.825NONO
CVE-2020-10600HIGH
An authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. This can result in blocking queries to PI Data Archive (2018
Jul 24, 20207.124NONO
View all 45 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products45 CVEs
58%
36%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local7 (15.6%)
Network31 (68.9%)
Unknown7 (15.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low34 (75.6%)
High4 (8.9%)
Unknown7 (15.6%)
User Interaction
None23 (51.1%)
Unknown7 (15.6%)
Required15 (33.3%)
Privileges Required
Low20 (44.4%)
High4 (8.9%)
None14 (31.1%)
Unknown7 (15.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (45 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Osisoft.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Osisoft — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Osisoft's Products

View all 2 CNAs →

Top CWEs