Описание
Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. As a result, an attacker with user privileges can gain arbitrary file write access with system access.
Ссылки
- Third Party AdvisoryUS Government Resource
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 9.6 (включая)
cpe:2.3:a:opto22:softpac_project:*:*:*:*:*:*:*:*
EPSS
Процентиль: 22%
0.00073
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-347
CWE-347
Связанные уязвимости
github
больше 3 лет назад
Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. As a result, an attacker with user privileges can gain arbitrary file write access with system access.
EPSS
Процентиль: 22%
0.00073
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-347
CWE-347