CVE-2020-10606 PUBLISHED CVSS 7.800000190734863 HIGH

In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software. This exploitation can result in unauthorized information disclosure, deletion, or modification if the local computer also processes PI System data from other users, such as from a shared workstation or terminal server deployment.

EPSS 0.06% · 18.0th percentile

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.06%
18.0th percentile

Affected Products

VendorProductVersions
n/aOSIsoft PI System multiple products and versionsOSIsoft PI System multiple products and versions
osisoftpi_api0, 0
osisoftpi_connector0, 0, 0
osisoftpi_connector_relay0
osisoftpi_to_ocs0
osisoftpi_integrator0
osisoftpi_interface_configuration_utility0
osisoftpi_buffer_subsystem0
osisoftpi_data_collection_manager0
osisoftpi_data_archive0

Timeline

References

Open in Interactive Console →