ZDI-23-1064: (0Day) Softing Secure Integration Server Hardcoded Cryptographic Key Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Softing Secure Integration Server. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1064?
The severity of ZDI-23-1064 is considered critical due to the potential for sensitive information disclosure.
How do I fix ZDI-23-1064?
To fix ZDI-23-1064, update your Softing Secure Integration Server to the latest patched version released by Softing.
Which software is affected by ZDI-23-1064?
ZDI-23-1064 affects the Softing Secure Integration Server.
Can ZDI-23-1064 be exploited without authentication?
While authentication is typically required, the vulnerability in ZDI-23-1064 allows for bypassing the existing authentication mechanism.
What impact does ZDI-23-1064 have on users?
ZDI-23-1064 can lead to unauthorized disclosure of sensitive information, putting user data at risk.