CVE-2020-10610: Osisoft Pi API
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification.
Affected products
- Osisoft Pi API: up to and including 1.6.8.26; up to and including 2.0.2.5
- Osisoft Pi Buffer Subsystem: up to and including 4.8.0.18
- Osisoft Pi Connector: up to and including 1.0.0.54; up to and including 1.1.0.10; up to and including 1.2.0.6; up to and including 1.2.0.42; up to and including 1.2.1.71; up to and including 1.2.2.79; …
- Osisoft Pi Connector Relay: up to and including 2.5.19.0
- Osisoft Pi Data Archive: up to and including 3.4.430.460
- Osisoft Pi Data Collection Manager: up to and including 2.5.19.0
- Osisoft Pi Integrator: up to and including 2.2.0.183
- Osisoft Pi Interface Configuration Utility: up to and including 1.5.0.7
- Osisoft Pi To Ocs: up to and including 1.1.36.0
Published 2020-07-24. Last modified 2026-06-17.