OSIsoft develops a focused but widely deployed suite of industrial data infrastructure software, with its vulnerability footprint concentrated in products such as PI Vision, PI Data Archive, PI Web API, and related components that serve as central repositories and interfaces for operational-technology environments. The exposure recurs through application-layer weakness classes including cross-site scripting, improper input validation, cross-site request forgery, authorization flaws, and sensitive-information leakage in logs—patterns typical of web-facing systems managing access to industrial datasets. A meaningful share of the vendor's vulnerabilities reach serious severity, reflecting the operational criticality of these products in manufacturing, utilities, and other process-heavy industries. Defenders should treat OSIsoft advisories as high-priority for any deployment in production environments and implement network segmentation and access controls around these data-tier systems; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Osisoft over time
Signals from CVEs in this vendor scope (45 CVEs).
45 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7500CRITICAL A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Privileges may be escalated, giving attackers access to the PI | Mar 14, 2018 | 9.8 | 31 | NO | NO |
CVE-2017-9653CRITICAL An Improper Authorization issue was discovered in OSIsoft PI Integrator for Business Analytics before 2016 R2, PI Integrator for Microsoft Azure before 2016 R2 SP1, and PI Integrat | Aug 14, 2017 | 9.8 | 31 | NO | NO |
CVE-2012-3008HIGH Stack-based buffer overflow in OSIsoft PI OPC DA Interface before 2.3.20.9 allows remote authenticated users to execute arbitrary code by sending packet data during the processing | Jul 20, 2012 | 8.5 | 28 | NO | NO |
CVE-2019-13516HIGH In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forgery protection setting that has not taken effect. | Aug 15, 2019 | 8.8 | 27 | NO | NO |
CVE-2017-7926HIGH A Cross-Site Request Forgery issue was discovered in OSIsoft PI Web API versions prior to 2017 (1.9.0). The vulnerability allows cross-site request forgery (CSRF) attacks to occur | Aug 25, 2017 | 8.8 | 27 | NO | NO |
CVE-2020-10608HIGH In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can ta | Jul 24, 2020 | 7.8 | 26 | NO | NO |
CVE-2020-10604HIGH In OSIsoft PI System multiple products and versions, a remote, unauthenticated attacker could crash PI Network Manager service through specially crafted requests. This can result i | Jul 25, 2020 | 7.5 | 25 | NO | NO |
CVE-2017-9641HIGH PI Coresight 2016 R2 contains a cross-site request forgery vulnerability that may allow access to the PI system. OSIsoft recommends that users upgrade to PI Vision 2017 or greater | May 25, 2018 | 8.8 | 25 | NO | NO |
CVE-2017-5153HIGH An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using the PI AF Services 2016 R2 integrated install kit. An infor | Feb 13, 2017 | 7.8 | 25 | NO | NO |
CVE-2020-10600HIGH An authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. This can result in blocking queries to PI Data Archive (2018 | Jul 24, 2020 | 7.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (45 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Osisoft.
Media articles that mention a CVE ID that affects a product developed by Osisoft — matched by CVE ID, not by vendor name.