CVE-2020-10610

HIGH

OSIsoft PI System - Privilege Escalation

Title source: llm

Description

In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification.

Scores

CVSS v3 7.8
EPSS 0.0011
EPSS Percentile 28.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427 CWE-426
Status published

Affected Products (20)

osisoft/pi_api < 1.6.8.26
osisoft/pi_api < 2.0.2.5
osisoft/pi_buffer_subsystem < 4.8.0.18
osisoft/pi_connector < 1.0.0.54
osisoft/pi_connector < 1.1.0.10
osisoft/pi_connector < 1.2.0.6
osisoft/pi_connector < 1.2.0.42
osisoft/pi_connector < 1.2.1.71
osisoft/pi_connector < 1.2.2.79
osisoft/pi_connector < 1.3.0.1
osisoft/pi_connector < 1.3.0.130
osisoft/pi_connector < 1.3.1.135
osisoft/pi_connector < 1.4.0.17
osisoft/pi_connector < 1.5.0.88
osisoft/pi_connector_relay < 2.5.19.0
... and 5 more

Timeline

Published Jul 24, 2020
Tracked Since Feb 18, 2026