CVE-2009-0209

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
01/10/2009
Last modified:
09/04/2025

Description

PI Server in OSIsoft PI System before 3.4.380.x does not properly use encryption in the default authentication process, which allows remote attackers to read or modify information in databases via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:osisoft:pi_server:*:sp2:32bit_windows:*:*:*:*:* 3.4.375.99 (including)
cpe:2.3:a:osisoft:pi_server:2.4:*:*:*:*:*:*:*
cpe:2.3:a:osisoft:pi_server:2.6:*:*:*:*:*:*:*
cpe:2.3:a:osisoft:pi_server:3.4.363.97:*:*:*:*:*:*:*
cpe:2.3:a:osisoft:pi_server:3.4.370:*:*:*:*:*:*:*
cpe:2.3:a:osisoft:pi_server:3.4.375.99:sp2:64bit_windows:*:*:*:*:*