ZeroHour

CVE-2020-10608

CVSS 3.1
7.8 high
EPSS
<1%p13
Published
()
Modified
Description

In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure, deletion, or modification.

Vendors
osisoft
Products
pi api, pi buffer subsystem, pi connector, pi connector relay, pi data archive, pi data collection manager, pi integrator, pi interface configuration utility, pi to ocs
Weakness
CWE-347
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.