ID

VAR-202007-0030


CVE

CVE-2020-10606


TITLE

plural OSIsoft Made PI Vulnerability in improper default permissions on system

Trust: 0.8

sources: JVNDB: JVNDB-2020-009001

DESCRIPTION

In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software. This exploitation can result in unauthorized information disclosure, deletion, or modification if the local computer also processes PI System data from other users, such as from a shared workstation or terminal server deployment. plural OSIsoft Made PI There is a vulnerability in the system regarding improper default permissions.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state

Trust: 1.71

sources: NVD: CVE-2020-10606 // JVNDB: JVNDB-2020-009001 // VULMON: CVE-2020-10606

AFFECTED PRODUCTS

vendor:osisoftmodel:pi interface configuration utilityscope:lteversion:1.5.0.7

Trust: 1.0

vendor:osisoftmodel:pi connectorscope:lteversion:1.1.0.10

Trust: 1.0

vendor:osisoftmodel:pi connectorscope:lteversion:1.2.0.42

Trust: 1.0

vendor:osisoftmodel:pi to ocsscope:lteversion:1.1.36.0

Trust: 1.0

vendor:osisoftmodel:pi connector relayscope:lteversion:2.5.19.0

Trust: 1.0

vendor:osisoftmodel:pi connectorscope:lteversion:1.0.0.54

Trust: 1.0

vendor:osisoftmodel:pi data collection managerscope:lteversion:2.5.19.0

Trust: 1.0

vendor:osisoftmodel:pi buffer subsystemscope:lteversion:4.8.0.18

Trust: 1.0

vendor:osisoftmodel:pi connectorscope:lteversion:1.2.0.6

Trust: 1.0

vendor:osisoftmodel:pi connectorscope:lteversion:1.3.0.130

Trust: 1.0

vendor:osisoftmodel:pi apiscope:lteversion:1.6.8.26

Trust: 1.0

vendor:osisoftmodel:pi connectorscope:lteversion:1.2.1.71

Trust: 1.0

vendor:osisoftmodel:pi connectorscope:lteversion:1.3.1.135

Trust: 1.0

vendor:osisoftmodel:pi apiscope:lteversion:2.0.2.5

Trust: 1.0

vendor:osisoftmodel:pi data archivescope:lteversion:3.4.430.460

Trust: 1.0

vendor:osisoftmodel:pi connectorscope:lteversion:1.2.2.79

Trust: 1.0

vendor:osisoftmodel:pi connectorscope:lteversion:1.3.0.1

Trust: 1.0

vendor:osisoftmodel:pi connectorscope:lteversion:1.4.0.17

Trust: 1.0

vendor:osisoftmodel:pi integratorscope:lteversion:2.2.0.183

Trust: 1.0

vendor:osisoftmodel:pi connectorscope:lteversion:1.5.0.88

Trust: 1.0

vendor:osisoftmodel:pi apiscope: - version: -

Trust: 0.8

vendor:osisoftmodel:pi buffer subsystemscope: - version: -

Trust: 0.8

vendor:osisoftmodel:pi connectorscope: - version: -

Trust: 0.8

vendor:osisoftmodel:pi connector relayscope: - version: -

Trust: 0.8

vendor:osisoftmodel:pi data archivescope: - version: -

Trust: 0.8

vendor:osisoftmodel:pi data collection managerscope: - version: -

Trust: 0.8

vendor:osisoftmodel:pi integrator for business analyticsscope: - version: -

Trust: 0.8

vendor:osisoftmodel:pi interface configuration utilityscope: - version: -

Trust: 0.8

vendor:osisoftmodel:pi to ocsscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-009001 // NVD: CVE-2020-10606

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-10606
value: HIGH

Trust: 1.0

NVD: JVNDB-2020-009001
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202005-689
value: HIGH

Trust: 0.6

VULMON: CVE-2020-10606
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-10606
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

NVD: JVNDB-2020-009001
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

nvd@nist.gov: CVE-2020-10606
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-009001
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULMON: CVE-2020-10606 // JVNDB: JVNDB-2020-009001 // CNNVD: CNNVD-202005-689 // NVD: CVE-2020-10606

PROBLEMTYPE DATA

problemtype:CWE-276

Trust: 1.8

sources: JVNDB: JVNDB-2020-009001 // NVD: CVE-2020-10606

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202005-689

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202005-689

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-009001

PATCH

title:Top Pageurl:https://www.osisoft.com/

Trust: 0.8

sources: JVNDB: JVNDB-2020-009001

EXTERNAL IDS

db:ICS CERTid:ICSA-20-133-02

Trust: 2.5

db:NVDid:CVE-2020-10606

Trust: 2.5

db:JVNid:JVNVU94872807

Trust: 0.8

db:JVNDBid:JVNDB-2020-009001

Trust: 0.8

db:AUSCERTid:ESB-2020.1679

Trust: 0.6

db:CNNVDid:CNNVD-202005-689

Trust: 0.6

db:VULMONid:CVE-2020-10606

Trust: 0.1

sources: VULMON: CVE-2020-10606 // JVNDB: JVNDB-2020-009001 // CNNVD: CNNVD-202005-689 // NVD: CVE-2020-10606

REFERENCES

url:https://us-cert.cisa.gov/ics/advisories/icsa-20-133-02

Trust: 1.9

url:https://nvd.nist.gov/vuln/detail/cve-2020-10606

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-10606

Trust: 0.8

url:https://jvn.jp/vu/jvnvu94872807/

Trust: 0.8

url:https://www.us-cert.gov/ics/advisories/icsa-20-133-02

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.1679/

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/276.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2020-10606 // JVNDB: JVNDB-2020-009001 // CNNVD: CNNVD-202005-689 // NVD: CVE-2020-10606

SOURCES

db:VULMONid:CVE-2020-10606
db:JVNDBid:JVNDB-2020-009001
db:CNNVDid:CNNVD-202005-689
db:NVDid:CVE-2020-10606

LAST UPDATE DATE

2024-11-23T21:11:48.171000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2020-10606date:2020-08-05T00:00:00
db:JVNDBid:JVNDB-2020-009001date:2020-10-13T00:00:00
db:CNNVDid:CNNVD-202005-689date:2020-07-27T00:00:00
db:NVDid:CVE-2020-10606date:2024-11-21T04:55:41.233

SOURCES RELEASE DATE

db:VULMONid:CVE-2020-10606date:2020-07-24T00:00:00
db:JVNDBid:JVNDB-2020-009001date:2020-10-13T00:00:00
db:CNNVDid:CNNVD-202005-689date:2020-05-12T00:00:00
db:NVDid:CVE-2020-10606date:2020-07-24T23:15:11.830