Pi Data Archive
Vendor:
First CVE: Aug 25, 2017 · Active for 8 years
11
Total CVEs
More Total CVEs than 89% of tracked products
3.7
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pi Data Archive over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 25, 2017
8 years ago
Most Recent CVE
Jul 25, 2020
2,192 days ago
CVE Severity & Scoring
Pi Data Archive11 CVEs
27%
73%
All CVEs352,719 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local5 (45.5%)
Network6 (54.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (72.7%)
High3 (27.3%)
Unknown0 (0.0%)
User Interaction
None11 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low6 (54.5%)
High0 (0.0%)
None5 (45.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-10608HIGH In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can ta | Jul 24, 2020 | 7.8 | 26 | NO | NO |
CVE-2020-10604HIGH In OSIsoft PI System multiple products and versions, a remote, unauthenticated attacker could crash PI Network Manager service through specially crafted requests. This can result i | Jul 25, 2020 | 7.5 | 25 | NO | NO |
CVE-2020-10600HIGH An authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. This can result in blocking queries to PI Data Archive (2018 | Jul 24, 2020 | 7.1 | 24 | NO | NO |
CVE-2018-7533HIGH An Incorrect Default Permissions issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Insecure default configuration may allow escalation of privileges that giv | Mar 14, 2018 | 7.8 | 24 | NO | NO |
CVE-2017-7930HIGH An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Data Archive has protocol flaws with the potential to expose ch | Aug 25, 2017 | 7.4 | 24 | NO | NO |
CVE-2018-7529HIGH A Deserialization of Untrusted Data issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Unauthenticated users may modify deserialized data to send custom reque | Mar 14, 2018 | 7.5 | 23 | NO | NO |
CVE-2018-7531MEDIUM An Improper Input Validation issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Unauthenticated users may use unvalidated custom requests to crash the server. | Mar 14, 2018 | 5.9 | 21 | NO | NO |
CVE-2017-7934MEDIUM An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Network Manager using older protocol versions contains a flaw t | Aug 25, 2017 | 5.9 | 21 | NO | NO |
CVE-2020-10610HIGH In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the | Jul 24, 2020 | 7.8 | 20 | NO | NO |
CVE-2020-10606HIGH In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software. This exploitation can result in unauthor | Jul 24, 2020 | 7.8 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Pi Data Archive
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2018 | 1 | 7.5 | 2.1% | 0 | 0 |
| 2017 | 2 | 6.8 | 0.9% | 0 | 0 |