CVE-2020-10608 PUBLISHED CVSS 7.800000190734863 HIGH

In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure, deletion, or modification.

EPSS 0.03% · 8.8th percentile

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.03%
8.8th percentile

Affected Products

VendorProductVersions
osisoftpi_connector0, 0, 0
osisoftpi_integrator0
osisoftpi_data_archive0
osisoftpi_to_ocs0
osisoftpi_connector_relay0
osisoftpi_data_collection_manager0
n/aOSIsoft PI System multiple products and versionsOSIsoft PI System multiple products and versions
osisoftpi_buffer_subsystem0
osisoftpi_interface_configuration_utility0
osisoftpi_api0, 0

Timeline

References

Open in Interactive Console →