CVE-2023-37572: High severity softing opc suite vulnerability
Published Dec 5, 2023
·Updated
Softing OPC Suite version 5.25 and before has Incorrect Access Control, allows attackers to obtain sensitive information via weak permissions in OSFdiscovery service. The service executable could be changed or the service could be deleted.
Affected Software
1 affected component
Softing OPC<5.30
Event History
Dec 5, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-37572?
CVE-2023-37572 has a medium severity level due to its potential to allow unauthorized information access.
2
How do I fix CVE-2023-37572?
To fix CVE-2023-37572, upgrade Softing OPC Suite to version 5.30 or later where the access control issue has been addressed.
3
What type of vulnerability is CVE-2023-37572?
CVE-2023-37572 is an Incorrect Access Control vulnerability that affects the OSF_discovery service.
4
Which versions of Softing OPC are affected by CVE-2023-37572?
Softing OPC Suite version 5.25 and earlier are affected by CVE-2023-37572.
5
What can attackers achieve by exploiting CVE-2023-37572?
Attackers can obtain sensitive information due to weak permissions in the OSF_discovery service.