PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-5153 Osisoft CVE debrief

CVE-2017-5153 is an information exposure issue in OSIsoft PI Coresight and PI Web API deployments. According to NVD, affected configurations include PI Coresight 2016 R2 and earlier, and PI Web API 2016 R2 when deployed using the PI AF Services 2016 R2 integrated install kit. The issue can expose service account passwords in server log files, which may enable unauthorized shutdown of affected PI services and possible reuse of domain credentials.

Vendor
Osisoft
Product
Unknown
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-10
Original CVE updated
2017-07-11
Advisory published
2017-01-10
Advisory updated
2017-07-11

Who should care

Administrators and operators responsible for OSIsoft PI Coresight or PI Web API deployments, especially environments that use the PI AF Services 2016 R2 integrated install kit. Security teams should also pay attention if service account credentials may have been logged or reused across related services.

Technical summary

NVD classifies the weakness as CWE-532 (Insertion of Sensitive Information into Log File). The vulnerability is described as an information exposure through server log files that may reveal service account passwords for affected services. NVD lists the CVSS v3.0 vector as AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating that a local attacker with limited privileges could gain high confidentiality, integrity, and availability impact if exposed credentials are recovered and misused.

Defensive priority

High. The issue can expose credentials that may be used to disrupt PI services and potentially access broader domain resources, so affected systems should be reviewed promptly for exposure and credential reuse risk.

Recommended defensive actions

  • Review the vendor and government advisories referenced by NVD for product-specific remediation guidance.
  • Identify affected PI Coresight and PI Web API installations, including deployments using the PI AF Services 2016 R2 integrated install kit.
  • Search relevant server logs for any exposed service account passwords or other sensitive credentials.
  • Rotate any service account passwords or domain credentials that may have been exposed in logs.
  • Restrict access to log files and ensure logging configurations do not record secrets or authentication material.
  • Upgrade or otherwise remediate affected installations according to vendor guidance for non-vulnerable versions.

Evidence notes

This debrief is based on the supplied NVD record and its references. NVD states the affected products and versions, the CWE-532 classification, and the CVSS v3.0 vector. NVD also references ICS-CERT advisory ICSA-17-010-01 and SecurityFocus BID 95355 as supporting sources. No KEV listing was supplied.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-5153 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-5153

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-5153 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5153

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.