6.6
CVE-2023-29377
- EPSS 0.49%
- Veröffentlicht 14.09.2026 00:00:00
- Zuletzt bearbeitet 22.09.2026 19:56:19
- Erkennungen
An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is possible to bypass limitations on assignment of a directory path to FileDirectory OPC UA objects and a file path to File OPC UA objects.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSofting
≫
Produkt
Secure Integration Server
Default Statusunaffected
Version <=
1.22
Version
0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.49% | 0.404 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MITRE | 6.6 | 0.7 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-23 Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
https://industrial.softing.com/fileadmin/psirt/downloads/syt-2023-02.html
https://industrial.softing.com/fileadmin/psirt/downloads/syt-2023-02.json
https://www.zerodayinitiative.com/advisories/ZDI-23-1055/