CVE-2020-10608
In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.22%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure, deletion, or modification.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.22% probability · 13th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-347
- Affected
- osisoft/pi api · osisoft/pi buffer subsystem · osisoft/pi connector · osisoft/pi connector relay · osisoft/pi data archive · osisoft/pi data collection manager · osisoft/pi integrator · osisoft/pi interface configuration utility · osisoft/pi to ocs
- Source
- ics-cert@hq.dhs.gov
References
- https://us-cert.cisa.gov/ics/advisories/icsa-20-133-02Third Party Advisory, US Government Resource
- https://us-cert.cisa.gov/ics/advisories/icsa-20-133-02Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.