OSIsoft PI Data Archive
OSIsoft PI Data Archive versions 2017 and earlier contain an input validation flaw (CWE-20) that allows remote attackers to trigger a denial of service condition. The service does not properly validate incoming requests, enabling an unauthenticated attacker on the network to craft a malicious request that causes the historian to stop responding. This affects data collection, storage, and availability of historical process data. No patch has been released; PI Data Archive 2017 and earlier are considered end-of-life products.
- Network access to PI Data Archive service port (typically port 5450)
- No authentication required
- PI Data Archive version 2017 or earlier
Patching may require device reboot — plan for process interruption
/api/v1/advisories/e29a0058-455c-4230-85bc-8b5502daa948Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.