4.6
CVSSv2

CVE-2020-10608

Published: 24/07/2020 Updated: 05/08/2020
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure, deletion, or modification.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

osisoft pi api

osisoft pi buffer subsystem

osisoft pi connector

osisoft pi connector relay

osisoft pi data archive

osisoft pi data collection manager

osisoft pi integrator

osisoft pi interface configuration utility

osisoft pi to ocs