Pi Web Api

Vendor:

First CVE: Feb 13, 2017 · Active for 9 years

8
Total CVEs
More Total CVEs than 85% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Pi Web Api over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 13, 2017
9 years ago
Most Recent CVE
Nov 18, 2021
1,709 days ago

CVE Severity & Scoring

Pi Web Api8 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local1 (12.5%)
Network7 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (37.5%)
Unknown0 (0.0%)
Required5 (62.5%)
Privileges Required
Low3 (37.5%)
High1 (12.5%)
None4 (50.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Privileges may be escalated, giving attackers access to the PI
Mar 14, 20189.831NONO
In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forgery protection setting that has not taken effect.
Aug 15, 20198.827NONO
A Cross-Site Request Forgery issue was discovered in OSIsoft PI Web API versions prior to 2017 (1.9.0). The vulnerability allows cross-site request forgery (CSRF) attacks to occur
Aug 25, 20178.827NONO
An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using the PI AF Services 2016 R2 integrated install kit. An infor
Feb 13, 20177.825NONO
In OSIsoft PI Web API 2019 Patch 1 (1.12.0.6346) and all previous versions, the affected product is vulnerable to a cross-site scripting attack, which may allow an attacker to remo
Jun 23, 20209.022NONO
OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information.
Aug 15, 20196.522NONO
A Cross-site Scripting issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Cross-site scripting may occur when input is incorrectly neutralized.
Mar 14, 20186.121NONO
A remote authenticated attacker with write access to a PI Server could trick a user into interacting with a PI Web API endpoint and redirect them to a malicious website. As a resul
Nov 18, 20214.818NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Pi Web Api

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
201919.01.6%00
201728.01.4%00
2016-r217.80.4%00
1.818.80.8%00