CVE-2020-10600: OSIsoft PI System
An authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. This can result in blocking queries to PI Data Archive (2018 SP2 and prior versions).
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10600?
CVE-2020-10600 has a severity that can allow an authenticated remote attacker to crash the PI Archive Subsystem.
How do I fix CVE-2020-10600?
You can fix CVE-2020-10600 by updating to the latest version of the affected software, specifically PI Data Archive 2018 SP3 or later.
Which versions are affected by CVE-2020-10600?
CVE-2020-10600 affects PI Data Archive versions prior to and including 2018 SP3, along with various other OSIsoft components.
What could happen if CVE-2020-10600 is exploited?
Exploitation of CVE-2020-10600 could lead to blocking queries to the PI Data Archive, impacting system functionality.
Is authentication required to exploit CVE-2020-10600?
Yes, an attacker must be authenticated to exploit CVE-2020-10600.