CVE-2020-10608: Osisoft Pi API

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure, deletion, or modification.

Affected products

  • Osisoft Pi API: up to and including 1.6.8.26; up to and including 2.0.2.5
  • Osisoft Pi Buffer Subsystem: up to and including 4.8.0.18
  • Osisoft Pi Connector: up to and including 1.0.0.54; up to and including 1.1.0.10; up to and including 1.2.0.6; up to and including 1.2.0.42; up to and including 1.2.1.71; up to and including 1.2.2.79; …
  • Osisoft Pi Connector Relay: up to and including 2.5.19.0
  • Osisoft Pi Data Archive: up to and including 3.4.430.460
  • Osisoft Pi Data Collection Manager: up to and including 2.5.19.0
  • Osisoft Pi Integrator: up to and including 2.2.0.183
  • Osisoft Pi Interface Configuration Utility: up to and including 1.5.0.7
  • Osisoft Pi To Ocs: up to and including 1.1.36.0

Published 2020-07-24. Last modified 2026-06-17.