ZDI-CAN-20548: ZDI-23-1061: (0Day) (Pwn2Own) Softing Secure Integration Server OPC UA Gateway Directory Creation Vulnerability
This vulnerability allows remote attackers to create directories on affected installations of Softing Secure Integration Server. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20548?
The severity of ZDI-CAN-20548 is high due to the potential for remote attackers to exploit the vulnerability after bypassing authentication.
How do I fix ZDI-CAN-20548?
To fix ZDI-CAN-20548, ensure that you update the Softing Secure Integration Server to the latest patched version provided by Softing.
What types of attacks can ZDI-CAN-20548 facilitate?
ZDI-CAN-20548 can facilitate remote directory creation attacks, potentially allowing attackers to manipulate the file system.
Is authentication required to exploit ZDI-CAN-20548?
Yes, authentication is required to exploit ZDI-CAN-20548, but the existing authentication mechanism can be bypassed.
Which software is affected by ZDI-CAN-20548?
ZDI-CAN-20548 affects the Softing Secure Integration Server.