CVE-2020-10610
HIGHOSIsoft PI System - Privilege Escalation
Title source: llmDescription
In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification.
Scores
CVSS v3
7.8
EPSS
0.0011
EPSS Percentile
28.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-427
CWE-426
Status
published
Affected Products (20)
osisoft/pi_api
< 1.6.8.26
osisoft/pi_api
< 2.0.2.5
osisoft/pi_buffer_subsystem
< 4.8.0.18
osisoft/pi_connector
< 1.0.0.54
osisoft/pi_connector
< 1.1.0.10
osisoft/pi_connector
< 1.2.0.6
osisoft/pi_connector
< 1.2.0.42
osisoft/pi_connector
< 1.2.1.71
osisoft/pi_connector
< 1.2.2.79
osisoft/pi_connector
< 1.3.0.1
osisoft/pi_connector
< 1.3.0.130
osisoft/pi_connector
< 1.3.1.135
osisoft/pi_connector
< 1.4.0.17
osisoft/pi_connector
< 1.5.0.88
osisoft/pi_connector_relay
< 2.5.19.0
... and 5 more
Timeline
Published
Jul 24, 2020
Tracked Since
Feb 18, 2026