An authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. This can result in blocking queries to PI Data Archive (2018 SP2 and prior versions).
Advisories
Source ID Title
EUVD EUVD EUVD-2020-3048 An authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. This can result in blocking queries to PI Data Archive (2018 SP2 and prior versions).
Fixes

Solution

Fully configure Windows authentication for the PI System and disable legacy authentication methods. For a starting point on PI System security best practices, see knowledge base article KB00833 -Seven best practices for securing your PI Server. (https://customers.osisoft.com/s/knowledgearticle?knowledgeArticleUrl=KB00833)


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-09-16T19:20:28.875Z

Reserved: 2020-03-16T00:00:00

Link: CVE-2020-10600

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-07-24T23:15:11.690

Modified: 2024-11-21T04:55:40.547

Link: CVE-2020-10600

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.