CVE-2020-10604: High severity osisoft pi data archive vulnerability
In OSIsoft PI System multiple products and versions, a remote, unauthenticated attacker could crash PI Network Manager service through specially crafted requests. This can result in blocking connections and queries to PI Data Archive.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10604?
CVE-2020-10604 is classified as a high severity vulnerability due to its ability to cause denial of service.
How do I fix CVE-2020-10604?
To fix CVE-2020-10604, upgrade to the latest versions of affected OSIsoft PI products as specified in the software vendor's release notes.
What impact does CVE-2020-10604 have on the PI Network Manager service?
CVE-2020-10604 allows a remote, unauthenticated attacker to crash the PI Network Manager service, disrupting connections and queries to the PI Data Archive.
Which OSIsoft products are affected by CVE-2020-10604?
CVE-2020-10604 affects multiple OSIsoft products including PI Data Archive, PI Asset Framework, and several PI Connectors and APIs.
Is authentication required to exploit CVE-2020-10604?
No, CVE-2020-10604 can be exploited by unauthenticated remote attackers.