Rewterz

Rewterz Threat Advisory – CVE-2019-10937 – Siemens SIMATIC TDC CP51M1 Denial of Service Vulnerability

September 11, 2019
Rewterz

Rewterz Threat Advisory – CVE-2019-10935 – Siemens SIMATIC WinCC and PCS7 Denial of Service Vulnerability

September 11, 2019

Rewterz Threat Advisory – CVE-2017-9765 – OSIsoft PI SQL Client Privilege Escalation Vulnerability

Severity

High

Analysis Summary

An attacker could exploit this vulnerability in a third-party component to remotely execute code on the client computer with the same permissions as the PI SQL Client user.

Communication with a malicious PI SQL Data Access Server (RTQP Engine) is needed to expose a PI SQL client to this vulnerability.

Impact

Privilege access

Affected Vendors

OSIsoft LLC

Affected Products

PI SQL Client 2018 (PI SQL Client OLEDB 2018)

Remediation

OSIsoft recommends users upgrade to PI SQL Client 2018 R2 or later to resolve this issue.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.