Impact
An issue exists in Softing OPC UA C++ SDK up to version 6.20 and in Softing Secure Integration Server up to version 1.22 that is a path traversal weakness (CWE-23). It allows an attacker to use FileType rename operations to bypass limits on what directory paths can be assigned to FileDirectory OPC UA objects and which file paths can be assigned to File objects. This loophole enables the attacker to reassign or redirect file system targets, potentially granting access to arbitrary files or directories that should otherwise be inaccessible through the OPC UA interface.
Affected Systems
The vulnerability affects Softing products: the OPC UA C++ SDK through version 6.20 and the Secure Integration Server through version 1.22. Clients or servers that implement these components may therefore be susceptible if they rely on the default path assignment logic.
Risk and Exploitability
The CVSS score of 6.6 indicates a medium severity vulnerability. The EPSS score is <1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote, relying on an attacker who can send OPC UA messages to the affected system to trigger the rename operation. Successful exploitation could lead to unauthorized access to filesystem content, potentially enabling further compromise if the system executes or processes those files.
OpenCVE Enrichment