Description
An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is possible to bypass limitations on assignment of a directory path to FileDirectory OPC UA objects and a file path to File OPC UA objects.
Published: 2026-09-14
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Path Traversal Bypass
Action: Apply Patch
AI Analysis

Impact

An issue exists in Softing OPC UA C++ SDK up to version 6.20 and in Softing Secure Integration Server up to version 1.22 that is a path traversal weakness (CWE-23). It allows an attacker to use FileType rename operations to bypass limits on what directory paths can be assigned to FileDirectory OPC UA objects and which file paths can be assigned to File objects. This loophole enables the attacker to reassign or redirect file system targets, potentially granting access to arbitrary files or directories that should otherwise be inaccessible through the OPC UA interface.

Affected Systems

The vulnerability affects Softing products: the OPC UA C++ SDK through version 6.20 and the Secure Integration Server through version 1.22. Clients or servers that implement these components may therefore be susceptible if they rely on the default path assignment logic.

Risk and Exploitability

The CVSS score of 6.6 indicates a medium severity vulnerability. The EPSS score is <1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote, relying on an attacker who can send OPC UA messages to the affected system to trigger the rename operation. Successful exploitation could lead to unauthorized access to filesystem content, potentially enabling further compromise if the system executes or processes those files.

Generated by OpenCVE AI on September 15, 2026 at 15:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Softing OPC UA C++ SDK to version 6.21 or later and the Secure Integration Server to version 1.23 or later
  • Disable or restrict FileType rename operations in the server configuration to prevent manipulation of file paths
  • Verify that FileDirectory and File OPC UA objects are configured with only intended, validated directory or file paths and audit configuration changes

Generated by OpenCVE AI on September 15, 2026 at 15:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Title File Type Rename Path Traversal Bypass in Softing OPC UA SDK and Secure Integration Server

Mon, 14 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Bypass via FileType Renames in Softing OPC UA SDK and Secure Integration Server

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Bypass via FileType Renames in Softing OPC UA SDK and Secure Integration Server

Mon, 14 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Softing
Softing secure Integration Server
Weaknesses CWE-23
CPEs cpe:2.3:a:softing:secure_integration_server:*:*:*:*:*:*:*:*
Vendors & Products Softing
Softing secure Integration Server
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Mon, 14 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is possible to bypass limitations on assignment of a directory path to FileDirectory OPC UA objects and a file path to File OPC UA objects.
References

Subscriptions

Softing Secure Integration Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T15:08:02.083Z

Reserved: 2023-04-05T00:00:00.000Z

Link: CVE-2023-29377

cve-icon Vulnrichment

Updated: 2026-09-14T15:07:57.783Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T05:16:56.987

Modified: 2026-09-22T19:56:19.073

Link: CVE-2023-29377

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:00:17Z

Weaknesses
  • CWE-23

    Relative Path Traversal