CVE Feed

    Dashboard / CVE / CVE-2017-5153

    CVE-2017-5153

    An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using the PI AF Services 2016 R2 integrated install kit. An information exposure through server log files vulnerability has been identified, which may allow service account passwords to become exposed for the affected services, potentially leading to unauthorized shutdown of the affected PI services as well as potential reuse of domain credentials.

    Published:Feb 13, 2017
    Last Modified:Apr 20, 2025
    EPS:Feb 13, 2017
    EPSS Score:0.00091
    CVSS Score:7.8

    Affected Products

    Vendor
    Osisoft
    Product
    Pi Coresight
    Vendor
    Osisoft
    Product
    Pi Web Api

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High