Softing Secure Integration Server Exposure of Resource to Wrong Sphere Remote Code Execution Vulnerability
CVE-2023-39478
8.8HIGH
What is CVE-2023-39478?
A vulnerability exists in Softing Secure Integration Server that exposes a flaw allowing remote attackers to execute arbitrary code on affected installations. This issue emerges from improper validation of user-supplied data during the handling of OPC FileDirectory namespaces. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed, making it easier for attackers to manipulate server objects. By leveraging this flaw alongside other vulnerabilities, an attacker can execute arbitrary code with elevated privileges, potentially leading to severe security implications.
Affected Version(s)
Secure Integration Server 1.22.0.8686
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
