In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure, deletion, or modification.

Project Subscriptions

Vendors Products
Osisoft Subscribe
Pi Buffer Subsystem Subscribe
Pi Connector Subscribe
Pi Connector Relay Subscribe
Pi Data Archive Subscribe
Pi Data Collection Manager Subscribe
Pi Integrator Subscribe
Pi Interface Configuration Utility Subscribe
Pi To Ocs Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-3056 In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure, deletion, or modification.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-04T11:06:09.916Z

Reserved: 2020-03-16T00:00:00

Link: CVE-2020-10608

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-07-24T23:15:11.877

Modified: 2024-11-21T04:55:41.463

Link: CVE-2020-10608

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses