CVE-2022-1373: Softing Secure Integration Server Relative Path Traversal
The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. An attacker can craft a zip file to load an arbitrary dll and execute code. Using the "restore configuration" feature to upload a zip file containing a path traversal file may cause a file to be created and executed upon touching the disk.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-1373.
What is the severity of CVE-2022-1373?
The severity of CVE-2022-1373 is high with a severity value of 7.2.
Which software is affected by CVE-2022-1373?
Softing Edgeaggregator version 3.1, Softing Edgeconnector version 3.1, Softing OPC version 5.2, Softing Opc Ua C++ Software Development Kit version 6, Softing Secure Integration Server version 1.22, and Softing Uagates version 1.74 are affected by CVE-2022-1373.
What is the description of CVE-2022-1373?
The "restore configuration" feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files, allowing an attacker to execute arbitrary code by crafting a malicious zip file.
How can I fix CVE-2022-1373?
Apply the latest security patch or update provided by Softing to mitigate CVE-2022-1373.