ZDI-23-1060: (0Day) (Pwn2Own) Softing Secure Integration Server Exposure of Resource to Wrong Sphere Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing Secure Integration Server. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1060?
ZDI-23-1060 is categorized as a critical vulnerability due to its ability to allow remote code execution.
How do I fix ZDI-23-1060?
To fix ZDI-23-1060, update Softing Secure Integration Server to the latest version that addresses this vulnerability.
Who is affected by ZDI-23-1060?
ZDI-23-1060 affects installations of Softing Secure Integration Server that have not implemented the necessary security updates.
What are the potential impacts of ZDI-23-1060?
Exploitation of ZDI-23-1060 could allow attackers to execute arbitrary code, potentially compromising the affected system and its data.
Is authentication required to exploit ZDI-23-1060?
Yes, authentication is required to exploit ZDI-23-1060, but the vulnerability allows for the bypass of existing authentication mechanisms.