ZDI-CAN-20504: ZDI-23-1057: (0Day) (Pwn2Own) Softing edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability
Published Aug 9, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
1 affected component
Softing edgeAggregator
Event History
Aug 9, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
May 3, 2024
Advisory Published
via ZDI·02:03 AM
Frequently Asked Questions
1
What is the severity of ZDI-CAN-20504?
The severity of ZDI-CAN-20504 is considered high due to its potential for remote code execution.
2
How do I fix ZDI-CAN-20504?
To fix ZDI-CAN-20504, you should apply the latest security updates provided by Softing for the edgeAggregator.
3
Who is affected by ZDI-CAN-20504?
ZDI-CAN-20504 affects installations of Softing edgeAggregator.
4
What type of attack does ZDI-CAN-20504 exploit?
ZDI-CAN-20504 exploits a vulnerability that allows remote attackers to execute arbitrary code.
5
Is user interaction required to exploit ZDI-CAN-20504?
Yes, user interaction is required for ZDI-CAN-20504 as the target must visit a malicious page or open a malicious file.