PT-2022-7027 · Softing · Softing Secure Integration Server+1

Published

2022-10-14

·

Updated

2023-08-09

·

CVE-2023-29377

CVSS v2.0

7.3

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions Softing OPC UA C++ SDK versions (affected versions not specified) Softing Secure Integration Server versions (affected versions not specified)
Description The issue is related to the incorrect restriction of a directory path name with limited access in the implementation of OPC UA methods in the Softing OPC UA C++ SDK and the Secure Integration Server data integration tool. This can allow a remote attacker to execute arbitrary code by exploiting the vulnerability.
Recommendations For Softing OPC UA C++ SDK, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Softing Secure Integration Server, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2023-06849
CVE-2023-29377
ZDI-23-1055

Affected Products

Softing Opc Ua C++ Sdk
Softing Secure Integration Server