Risk Summary
Successful exploitation of these vulnerabilities may allow direct attacks against the product and disclose sensitive information.
CVEs (2)
Remediations
- OSIsoft recommends users upgrade to PI Web API 2018 SP1 or later to resolve these issues. To download PI Web API 2018 SP1, please access the OSIsoft customer portal (login required).
- To avoid exposing sensitive information in the PI Web API Application Debug log, ensure that the Debug log is disabled on the Windows machine running PI Web API. Follow these steps to disable the Debug log: 1. Open Command Prompt and run the command eventvwr.msc. 2. Navigate to View > Show Analytic and Debug Logs. 3. Under Applications and Services Logs, find the PIWebAPI folder. 4. Right click on the log entitled Debug, and click Disable Log.
- Also be sure to clear existing entries in the Debug log.
- Assuming the log is Disabled but contains Events (e.g., after a troubleshooting session), enable the log and then disable it immediately.
- If the log is already enabled, disable it, enable it, and finally disable it again to wipe out the contents.
- The CSRF defense is enabled by default in new installations of PI Web API. OSIsoft recommends leaving the EnableCSRFDefense configuration setting unchanged so that the CSRF defense is always in effect. If it is necessary to toggle this setting, OSIsoft recommends restarting the PI Web API service after changing the state.
- For more information on these vulnerabilities, please refer to OSIsoft's Security Bulletin:PI Web API Multiple security vulnerabilities resolved
Affected Vendors
OSIsoft LLC
Affected Products (1)
OSIsoft LLC
·
PI Web API
<= 2018
Affected Sectors
Chemical, Critical Manufacturing, Energy, Food and Agriculture, Government Facilities, Healthcare and Public Health, Information Technology, Metals and Mining, Water and Wastewater Systems
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more