File Directory Path Bypass in Softing OPC UA C++ SDK and Secure Integration Server
CVE-2023-29377

6.6MEDIUM

Key Information:

Vendor

Softing

Vendor
CVE Published:
14 September 2026

What is CVE-2023-29377?

A vulnerability in Softing's OPC UA C++ SDK and Secure Integration Server allows exploitation through FileType renames. This issue enables attackers to bypass restrictions imposed on the assignment of directory paths to FileDirectory OPC UA objects and file paths to File OPC UA objects, potentially leading to unauthorized access and manipulation of files.

Affected Version(s)

Secure Integration Server 0 <= 1.22

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.