CVE-2021-43551
Last modified
CVE-2021-43551 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. A remote attacker with write access to PI Vision could inject code into a display. Unauthorized information disclosure, modification, or deletion is possible if a victim views or interacts with the infected display using Microsoft Internet Explorer. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
A remote attacker with write access to PI Vision could inject code into a display. Unauthorized information disclosure, modification, or deletion is possible if a victim views or interacts with the infected display using Microsoft Internet Explorer. The impact affects PI System data and other data accessible with victim's user permissions.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Osisoft | Pi Vision | < 2021 |
References
- https://us-cert.cisa.gov/ics/advisories/icsa-21-313-05Third Party Advisory, US Government Resource
- https://us-cert.cisa.gov/ics/advisories/icsa-21-313-05Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-43551?
How severe is CVE-2021-43551?
How do I fix CVE-2021-43551?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-43546It was possible to recreate previous cursor spoofing attacks…4.3
- CVE-2021-43547TwinOaks Computing CoreDX DDS versions prior to 5.9.1 are su…8.2
- CVE-2021-43548Patient Information Center iX (PIC iX) Versions C.02 and C.0…6.5
- CVE-2021-43549A remote authenticated attacker with write access to a PI Se…4.8
- CVE-2021-4355The Welcart e-Commerce plugin for WordPress is vulnerable to…5.3
- CVE-2021-43550The use of a broken or risky cryptographic algorithm is an u…6.5
- CVE-2021-43552The use of a hard-coded cryptographic key significantly incr…5.5
- CVE-2021-43553PI Vision could disclose information to a user with insuffic…4.3
- CVE-2021-43554FATEK WinProladder Versions 3.30_24518 and prior are vulnera…7.8
- CVE-2021-43555mySCADA myDESIGNER Versions 8.20.0 and prior fails to proper…7.8
- CVE-2021-43556FATEK WinProladder Versions 3.30_24518 and prior are vulnera…7.8
- CVE-2021-43557The uri-block plugin in Apache APISIX before 2.10.2 uses $re…7.5
Are you affected by CVE-2021-43551?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
