Softing Secure Integration Server OPC UA Gateway Directory Creation Vulnerability
CVE-2023-39479
8.8HIGH
What is CVE-2023-39479?
This vulnerability in the Softing Secure Integration Server OPC UA Gateway permits remote attackers to create directories on vulnerable installations. Despite requiring authentication for exploitation, the existing mechanism is susceptible to bypass. The vulnerability stems from improper handling of FileDirectory OPC UA Objects, allowing unauthorized access to the filesystem. Attackers can exploit this weakness, particularly when combined with other vulnerabilities, to execute arbitrary code with elevated privileges, raising significant security concerns for users of the affected product.
Affected Version(s)
Secure Integration Server 1.22.0.8686
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
