CVE-2020-10610: Osisoft Pi API

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification.

Affected products

  • Osisoft Pi API: up to and including 1.6.8.26; up to and including 2.0.2.5
  • Osisoft Pi Buffer Subsystem: up to and including 4.8.0.18
  • Osisoft Pi Connector: up to and including 1.0.0.54; up to and including 1.1.0.10; up to and including 1.2.0.6; up to and including 1.2.0.42; up to and including 1.2.1.71; up to and including 1.2.2.79; …
  • Osisoft Pi Connector Relay: up to and including 2.5.19.0
  • Osisoft Pi Data Archive: up to and including 3.4.430.460
  • Osisoft Pi Data Collection Manager: up to and including 2.5.19.0
  • Osisoft Pi Integrator: up to and including 2.2.0.183
  • Osisoft Pi Interface Configuration Utility: up to and including 1.5.0.7
  • Osisoft Pi To Ocs: up to and including 1.1.36.0

Published 2020-07-24. Last modified 2026-06-17.