CVE-2020-10610: High severity osisoft pi asset framework (af) client vulnerability
In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10610?
CVE-2020-10610 is a vulnerability in OSIsoft PI System that allows a local attacker to take control of the local computer at Windows system privilege level.
Which products and versions are affected by CVE-2020-10610?
OSIsoft PI System products and versions such as Osisoft Pi API, Osisoft Pi Buffer Subsystem, and Osisoft Pi Connector are affected by CVE-2020-10610.
What is the severity of CVE-2020-10610?
CVE-2020-10610 has a severity rating of 7.8, which is considered high.
How can a local attacker exploit CVE-2020-10610?
A local attacker can exploit CVE-2020-10610 by modifying a search path and planting a binary to gain unauthorized control over the affected PI System software.
Where can I find more information about CVE-2020-10610?
You can find more information about CVE-2020-10610 at the following reference: https://us-cert.cisa.gov/ics/advisories/icsa-20-133-02