Pi Web Api
Vendor:
First CVE: Feb 13, 2017 · Active for 9 years
8
Total CVEs
More Total CVEs than 85% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pi Web Api over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 13, 2017
9 years ago
Most Recent CVE
Nov 18, 2021
1,709 days ago
CVE Severity & Scoring
Pi Web Api8 CVEs
38%
38%
25%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (12.5%)
Network7 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (37.5%)
Unknown0 (0.0%)
Required5 (62.5%)
Privileges Required
Low3 (37.5%)
High1 (12.5%)
None4 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7500CRITICAL A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Privileges may be escalated, giving attackers access to the PI | Mar 14, 2018 | 9.8 | 31 | NO | NO |
CVE-2019-13516HIGH In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forgery protection setting that has not taken effect. | Aug 15, 2019 | 8.8 | 27 | NO | NO |
CVE-2017-7926HIGH A Cross-Site Request Forgery issue was discovered in OSIsoft PI Web API versions prior to 2017 (1.9.0). The vulnerability allows cross-site request forgery (CSRF) attacks to occur | Aug 25, 2017 | 8.8 | 27 | NO | NO |
CVE-2017-5153HIGH An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using the PI AF Services 2016 R2 integrated install kit. An infor | Feb 13, 2017 | 7.8 | 25 | NO | NO |
CVE-2020-12021CRITICAL In OSIsoft PI Web API 2019 Patch 1 (1.12.0.6346) and all previous versions, the affected product is vulnerable to a cross-site scripting attack, which may allow an attacker to remo | Jun 23, 2020 | 9.0 | 22 | NO | NO |
CVE-2019-13515MEDIUM OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information. | Aug 15, 2019 | 6.5 | 22 | NO | NO |
CVE-2018-7508MEDIUM A Cross-site Scripting issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Cross-site scripting may occur when input is incorrectly neutralized. | Mar 14, 2018 | 6.1 | 21 | NO | NO |
CVE-2021-43549MEDIUM A remote authenticated attacker with write access to a PI Server could trick a user into interacting with a PI Web API endpoint and redirect them to a malicious website. As a resul | Nov 18, 2021 | 4.8 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Pi Web Api
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2019 | 1 | 9.0 | 1.6% | 0 | 0 |
| 2017 | 2 | 8.0 | 1.4% | 0 | 0 |
| 2016-r2 | 1 | 7.8 | 0.4% | 0 | 0 |
| 1.8 | 1 | 8.8 | 0.8% | 0 | 0 |