CVE-2017-5153 - CVE House
Back to Database
Status published High CVE-2017-5153

An issue was discovered in OSIsoft PI Coresight 2016 R2...

Vulnerability Description

An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using the PI AF Services 2016 R2 integrated install kit. An information exposure through server log files vulnerability has been identified, which may allow service account passwords to become exposed for the affected services, potentially leading to unauthorized shutdown of the affected PI services as well as potential reuse of domain credentials.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-5153

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

OSIsoft PI Coresight and PI Web API
Vulnerable Versions:
OSIsoft PI Coresight and PI Web API

Timeline

Official Publish: February 13th, 2017
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.