VYPR

Pi API

by Osisoft

CVEs (4)

  • CVE-2020-12021CriJun 23, 2020
    risk 0.59cvss 9.0epss 0.02

    In OSIsoft PI Web API 2019 Patch 1 (1.12.0.6346) and all previous versions, the affected product is vulnerable to a cross-site scripting attack, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2020-10610HigJul 24, 2020
    risk 0.51cvss 7.8epss 0.00

    In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure,…

  • CVE-2020-10608HigJul 24, 2020
    risk 0.51cvss 7.8epss 0.00

    In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in…

  • CVE-2020-10606HigJul 24, 2020
    risk 0.51cvss 7.8epss 0.00

    In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software. This exploitation can result in unauthorized information disclosure, deletion, or modification if the local computer also processes PI…