ZeroHour

CVE-2020-10610

CVSS 3.1
7.8 high
EPSS
<1%p31
Published
()
Modified
Description

In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification.

Vendors
osisoft
Products
pi api, pi buffer subsystem, pi connector, pi connector relay, pi data archive, pi data collection manager, pi integrator, pi interface configuration utility, pi to ocs
Weakness
CWE-427, CWE-426
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.