SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-10606

In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software.

HIGH 7.8EPSS 0.27%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.27%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software. This exploitation can result in unauthorized information disclosure, deletion, or modification if the local computer also processes PI System data from other users, such as from a shared workstation or terminal server deployment.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.27% probability · 19th percentile
CISA KEV
Not listed
Weakness
CWE-276
Affected
osisoft/pi api · osisoft/pi buffer subsystem · osisoft/pi connector · osisoft/pi connector relay · osisoft/pi data archive · osisoft/pi data collection manager · osisoft/pi integrator · osisoft/pi interface configuration utility · osisoft/pi to ocs
Source
ics-cert@hq.dhs.gov

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.