← Back to home
ICSA-20-133-02  ·  Published 2020-06-09  ·  View on CISA ICS-CERT ↗

OSIsoft PI System (Update A)

CVSS 7.8 HIGH

Risk Summary

Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized information, delete or modify local processes, and crash the affected device.

Remediations

  • OSIsoft provides the following security updates to mitigate the reported vulnerabilities:
  • OSIsoft reports further action should be taken after applying the security updates. Remove PI Asset Framework (AF) Client .NET 3.5 after verifying OSIsoft products that include the PI AF Client, such as PI ProcessBook, PI DataLink and other PI System desktop applications have been upgraded to 2015 (as well as later versions) in order to eliminate exposure to CVE-2020-10608.
  • For PI System servers and interface nodes that are normally unattended, limit console and remote desktop logon access to authorized administrators.
  • Individual updates for core PI System components are available. Additionally, the following OSIsoft product installation kits have been re-released to automatically deliver the updated components:
  • Client
  • Server
  • Connectors
  • OSIsoft reports not all products have been rebundled to include the affected update.
  • Contact OSIsoft support for guidance on products missing that use affected components that are missing from the currently available releases.
  • CVE-2020-10610 Manage permissions on HKLM\Software\PISystem and HKLM\WOW6432Node\Software\PISystem registry keys to block a high impact exploit path. See OSIsoft customer portal knowledge article PI System Registry Security Recommendations for details on setting registry permissions.
  • CVE-2019-18244 Provision and use domain Group Managed Service Accounts or use the default NetworkService account to run PI Vision AppPools. There is no exposure to this vulnerability when using either of these account types. To limit exposure in case standard domain account is used to run PI Vision AppPools, remove the password entry from the setup log files immediately. OSIsoft reports the following measures can be used to lower likelihood of exploitation:
  • CVE-2020-10610, CVE-2020-10608, CVE-2020-10606 Migrate standard users to PI Vision and browser-based access to PI System data.
  • CVE-2020-10608 Restrict network connections from PI client workstations to trusted AF servers (TCP Port 5457).
  • CVE-2020-10606 Disable unused PI Buffering services from PI client workstations (PI Buffer Subsystem, PI Buffer Server).
  • CVE-2019-10768, CVE-2020-10600, CVE-2020-10614 Limit write access to PI Vision displays to trusted users.
  • The following measures can be used to lower the potential impact of exploitation:
  • CVE-2020-10610 and CVE-2020-10608 Deploy application whitelisting solutions with enforcement for approved DLLs:
  • For a list of PI System firewall port requirements, see knowledge base article KB01162 - Firewall Port Requirements.
  • CVE-2020-10604, CVE-2020-10602, CVE-2020-10600 Fully configure Windows authentication for the PI System and disable legacy authentication methods. For a starting point on PI System security best practices, see knowledge base article KB00833 - Seven best practices for securing your PI Server.
  • For more information and workaround details for these vulnerabilities, please refer to OSIsoft 's Security Bulletin (registration required): OSIsoft Updates PI System and Common Components.

Affected Vendors

OSIsoft LLC

Affected Products (28)

OSIsoft LLC · PI Connector for BACnet <= 1.2.0.6
OSIsoft LLC · PI API for Windows Integrated Security <= 2.0.2.5
OSIsoft LLC · Applications using PI Software Development Kit (SDK) <= PI SDK 2018 SP1 Version 1.4.7.602
OSIsoft LLC · PI Data Archive 2018 | 2018 SP2
OSIsoft LLC · PI Connector for UFL <= 1.3.1.135
OSIsoft LLC · PI Connector for Siemens Simatic PCS 7 <= 1.2.1.71
OSIsoft LLC · PI Connector for CygNet <= 1.4.0.17
OSIsoft LLC · PI Connector for DC Systems RTscada <= 1.2.0.42
OSIsoft LLC · PI to OCS <= 1.1.36.0
OSIsoft LLC · PI Connector for Ping <= 1.0.0.54
OSIsoft LLC · PI Data Collection Manager <= 2.5.19.0
OSIsoft LLC · PI Data Archive <= 2018 SP3 Version 3.4.430.460
OSIsoft LLC · PI Integrator for Business Analytics <= 2018 R2 SP1 Version 2.2.0.183
OSIsoft LLC · PI Manual Logger <= 2017 R2 Patch 1
OSIsoft LLC · PI Connector for Ethernet/IP <= 1.1.0.10
OSIsoft LLC · PI Connector for Wonderware Historian <= 1.5.0.88
OSIsoft LLC · PI Vision <= 2019
OSIsoft LLC · Applications using PI Asset Framework (AF) Client <= PI AF Client 2018 SP3 Patch 1 Version 2.10.7.283
OSIsoft LLC · PI Data Archive <= 2018 SP2
OSIsoft LLC · RtReports <= 4.1
OSIsoft LLC · PI Connector for OPC-UA <= 1.3.0.130
OSIsoft LLC · PI Connector Relay <= 2.5.19.0
OSIsoft LLC · PI Connector for IEC 60870-5-104 versions <= 1.2.2.79
OSIsoft LLC · PI Buffer Subsystem <= 4.8.0.18
OSIsoft LLC · PI Interface Configuration Utility (ICU) <= 1.5.0.7
OSIsoft LLC · PI Connector for HART-IP <= 1.3.0.1
OSIsoft LLC · PI Vision <= 2019
OSIsoft LLC · PI API <= 1.6.8.26

Affected Sectors

Multiple Sectors

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more