ZDI-CAN-21225: ZDI-24-352: Softing edgeConnector Siemens Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeConnector Siemens. Authentication is required to exploit this vulnerability. In the case of a network-adjacent attacker, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2023-38126.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21225?
ZDI-CAN-21225 is considered to have a high severity due to its potential for remote code execution.
How do I fix ZDI-CAN-21225?
To fix ZDI-CAN-21225, ensure that all affected installations of Softing edgeConnector Siemens are updated to the latest version provided by the vendor.
What does ZDI-CAN-21225 allow attackers to do?
ZDI-CAN-21225 allows remote attackers to execute arbitrary code on affected installations of Softing edgeConnector Siemens.
Is authentication required to exploit ZDI-CAN-21225?
Yes, authentication is required to exploit ZDI-CAN-21225, but it can be bypassed by network-adjacent attackers.
Which software is affected by ZDI-CAN-21225?
The software affected by ZDI-CAN-21225 is Softing edgeConnector Siemens.