Softing Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerability
CVE-2023-39481

8.8HIGH

Key Information:

Vendor

Softing

Vendor
CVE Published:
3 May 2024

What is CVE-2023-39481?

A vulnerability within the Softing Secure Integration Server enables remote attackers to execute arbitrary code under certain conditions. This issue arises from inconsistencies in URI parsing between the NGINX web server and the application code. Even though the vulnerability requires authentication for exploitation, the existing authentication mechanism can be bypassed, which significantly increases the risk of unauthorized access. Attackers may exploit this vulnerability in conjunction with other security weaknesses, potentially executing malicious code in a privileged context, leading to severe consequences for affected installations.

Affected Version(s)

Secure Integration Server 1.22.0.8686

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.