Overview
OSIsoft PI Server provides an insecure authentication mechanism that could allow attackers to read or modify information in databases.
Description
PI Server is a core component of the OSIsoft PI System. According to a report from C4 Security, OSISoft release notes (login required) for PI Server 3.4.380.36, and OSISoft KB article 5120OSI8, it appears that changes were made to PI Server to better resist brute force authentication attempts. PI Server 3.4.380.36 deprecates an older authentication mechanism in favor of Microsoft Windows authentication. |
Impact
According to reports it appears that the old PI Sever integrated authentication security system method was susceptible to brute force authentication attempts. A successful attempt will allow an attacker to gain access to the PI Server databases. |
Solution
OSIsoft recommends upgrading to PI Server version 3.4.380.36. |
According to the PI Server 3.4.380.36 release notes the following procedures to mitigate the vulnerability: |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Eyal Udassin at C4 Security for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2009-0209 |
Severity Metric: | 11.76 |
Date Public: | 2009-09-30 |
Date First Published: | 2010-11-19 |
Date Last Updated: | 2010-11-19 18:16 UTC |
Document Revision: | 37 |