ZDI-23-1057: (0Day) (Pwn2Own) Softing edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1057?
The severity of ZDI-23-1057 is considered critical due to its potential for remote code execution.
How do I fix ZDI-23-1057?
To fix ZDI-23-1057, update your Softing edgeAggregator software to the latest patched version.
What systems are affected by ZDI-23-1057?
ZDI-23-1057 affects installations of Softing edgeAggregator that are not updated to include the necessary security patches.
Can ZDI-23-1057 be exploited without user interaction?
No, ZDI-23-1057 requires user interaction whereby the target must visit a malicious page or open a harmful file.
What type of vulnerability is ZDI-23-1057?
ZDI-23-1057 is a remote code execution vulnerability that allows attackers to execute arbitrary code on affected systems.