CVE-2020-10610

HIGH

OSIsoft PI System - Privilege Escalation

Title source: llm
STIX 2.1

Description

In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-20-133-02

Scores

CVSS v3 7.8
EPSS 0.0038
EPSS Percentile 29.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-427 CWE-426
Status published
Products (20)
osisoft/pi_api < 1.6.8.26
osisoft/pi_api < 2.0.2.5
osisoft/pi_buffer_subsystem < 4.8.0.18
osisoft/pi_connector < 1.0.0.54
osisoft/pi_connector < 1.1.0.10
osisoft/pi_connector < 1.2.0.42
osisoft/pi_connector < 1.2.0.6
osisoft/pi_connector < 1.2.1.71
osisoft/pi_connector < 1.2.2.79
osisoft/pi_connector < 1.3.0.1
... and 10 more
Published Jul 24, 2020
Tracked Since Feb 18, 2026