CVE-2020-10608

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/07/2020
Last modified:
05/08/2020

Description

In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure, deletion, or modification.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:osisoft:pi_api:*:*:*:*:*:*:*:* 1.6.8.26 (including)
cpe:2.3:a:osisoft:pi_api:*:*:*:*:*:windows_integrated_security:*:* 2.0.2.5 (including)
cpe:2.3:a:osisoft:pi_buffer_subsystem:*:*:*:*:*:*:*:* 4.8.0.18 (including)
cpe:2.3:a:osisoft:pi_connector:*:*:*:*:*:ping:*:* 1.0.0.54 (including)
cpe:2.3:a:osisoft:pi_connector:*:*:*:*:*:ethernet\/ip:*:* 1.1.0.10 (including)
cpe:2.3:a:osisoft:pi_connector:*:*:*:*:*:bacnet:*:* 1.2.0.6 (including)
cpe:2.3:a:osisoft:pi_connector:*:*:*:*:*:dc_systems_rtscada:*:* 1.2.0.42 (including)
cpe:2.3:a:osisoft:pi_connector:*:*:*:*:*:siemens_simatic_pcs_7:*:* 1.2.1.71 (including)
cpe:2.3:a:osisoft:pi_connector:*:*:*:*:*:iec_60870-5-104:*:* 1.2.2.79 (including)
cpe:2.3:a:osisoft:pi_connector:*:*:*:*:*:hart-ip:*:* 1.3.0.1 (including)
cpe:2.3:a:osisoft:pi_connector:*:*:*:*:*:opc-ua:*:* 1.3.0.130 (including)
cpe:2.3:a:osisoft:pi_connector:*:*:*:*:*:ufl:*:* 1.3.1.135 (including)
cpe:2.3:a:osisoft:pi_connector:*:*:*:*:*:cygnet:*:* 1.4.0.17 (including)
cpe:2.3:a:osisoft:pi_connector:*:*:*:*:*:wonderware_historian:*:* 1.5.0.88 (including)
cpe:2.3:a:osisoft:pi_connector_relay:*:*:*:*:*:*:*:* 2.5.19.0 (including)


References to Advisories, Solutions, and Tools