ZDI-CAN-20549: ZDI-23-1062: (0Day) (Pwn2Own) Softing Secure Integration Server FileDirectory OPC UA Object Arbitrary File Creation Vulnerability
This vulnerability allows remote attackers to create arbitrary files on affected installations of Softing Secure Integration Server. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20549?
The severity of ZDI-CAN-20549 is significant due to the potential for remote file creation by attackers.
How do I fix ZDI-CAN-20549?
To fix ZDI-CAN-20549, update to the latest version of Softing Secure Integration Server that addresses this vulnerability.
What are the potential impacts of ZDI-CAN-20549?
Exploiting ZDI-CAN-20549 can lead to unauthorized file creation on affected systems, compromising confidentiality and integrity.
Is authentication required to exploit ZDI-CAN-20549?
Yes, authentication is required; however, the existing authentication mechanism can be bypassed.
Which systems are affected by ZDI-CAN-20549?
ZDI-CAN-20549 affects installations of Softing Secure Integration Server.