CVE-2020-10614: XSS
In OSIsoft PI System multiple products and versions, an authenticated remote attacker with write access to PI Vision databases could inject code into a display. Unauthorized information disclosure, deletion, or modification is possible if a victim views the infected display.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10614?
CVE-2020-10614 is a vulnerability in OSIsoft PI System that allows an authenticated remote attacker with write access to inject code into a display, leading to unauthorized information disclosure, deletion, or modification.
How severe is CVE-2020-10614?
The severity of CVE-2020-10614 is medium with a CVSS score of 4.8.
Which products and versions are affected by CVE-2020-10614?
OSIsoft PI Vision versions up to 2019 are affected by CVE-2020-10614.
How can I fix CVE-2020-10614?
Apply the latest updates or patches provided by OSIsoft to address CVE-2020-10614.
Where can I find more information about CVE-2020-10614?
You can find more information about CVE-2020-10614 at the following link: [https://us-cert.cisa.gov/ics/advisories/icsa-20-133-02](https://us-cert.cisa.gov/ics/advisories/icsa-20-133-02)