CVE-2020-10606: Osisoft Pi API
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software. This exploitation can result in unauthorized information disclosure, deletion, or modification if the local computer also processes PI System data from other users, such as from a shared workstation or terminal server deployment.
Affected products
- Osisoft Pi API: up to and including 1.6.8.26; up to and including 2.0.2.5
- Osisoft Pi Buffer Subsystem: up to and including 4.8.0.18
- Osisoft Pi Connector: up to and including 1.0.0.54; up to and including 1.1.0.10; up to and including 1.2.0.6; up to and including 1.2.0.42; up to and including 1.2.1.71; up to and including 1.2.2.79; …
- Osisoft Pi Connector Relay: up to and including 2.5.19.0
- Osisoft Pi Data Archive: up to and including 3.4.430.460
- Osisoft Pi Data Collection Manager: up to and including 2.5.19.0
- Osisoft Pi Integrator: up to and including 2.2.0.183
- Osisoft Pi Interface Configuration Utility: up to and including 1.5.0.7
- Osisoft Pi To Ocs: up to and including 1.1.36.0
Published 2020-07-24. Last modified 2026-06-17.