CVE-2020-10608: High severity osisoft pi asset framework (af) client vulnerability
In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure, deletion, or modification.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this OSIsoft PI System vulnerability?
The vulnerability ID is CVE-2020-10608.
What is the severity rating of CVE-2020-10608?
The severity rating of CVE-2020-10608 is 7.8 (high).
Which products and versions are affected by CVE-2020-10608?
The affected products and versions are: Osisoft Pi Api 1.6.8.26, Osisoft Pi Api 2.0.2.5 (with Windows Integrated Security), Osisoft Pi Buffer Subsystem 4.8.0.18, Osisoft Pi Connector 1.0.0.54 (Ping), Osisoft Pi Connector 1.1.0.10 (Ethernet/IP), Osisoft Pi Connector 1.2.0.6 (BACnet), Osisoft Pi Connector 1.2.0.42 (DC Systems RTSCADA), Osisoft Pi Connector 1.2.1.71 (Siemens SIMATIC PCS 7), Osisoft Pi Connector 1.2.2.79 (IEC 60870-5-104), Osisoft Pi Connector 1.3.0.1 (HART-IP), Osisoft Pi Connector 1.3.0.130 (OPC-UA), Osisoft Pi Connector 1.3.1.135 (UFL), Osisoft Pi Connector 1.4.0.17 (CygNet), Osisoft Pi Connector 1.5.0.88 (Wonderware Historian), Osisoft Pi Connector Relay 2.5.19.0, OSIsoft PI Data Archive 3.4.430.460, Osisoft Pi Data Collection Manager 2.5.19.0, Osisoft Pi Integrator 2.2.0.183 (Business Analytics), Osisoft Pi Interface Configuration Utility 1.5.0.7, Osisoft Pi To Ocs 1.1.36.0.
What can a local attacker do with this vulnerability?
A local attacker can plant a binary and bypass a code integrity check to escalate privileges and gain unauthorized information access.
Is there a fix available for CVE-2020-10608?
Yes, a fix is available for CVE-2020-10608. Please refer to the official reference for more information.