Description
Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. As a result, an attacker with user privileges can gain arbitrary file write access with system access.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-4358 | Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. As a result, an attacker with user privileges can gain arbitrary file write access with system access. |
References
| Link | Providers |
|---|---|
| https://www.us-cert.gov/ics/advisories/icsa-20-135-01 |
|
History
No history.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-04T11:48:57.821Z
Reserved: 2020-04-21T00:00:00.000Z
Link: CVE-2020-12042
No data.
Status : Modified
Published: 2020-05-14T21:15:13.103
Modified: 2024-11-21T04:59:10.177
Link: CVE-2020-12042
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD