Vulnerability Description
Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. As a result, an attacker with user privileges can gain arbitrary file write access with system access.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opto22 | Softpac Project | <= 9.6 |
Related Weaknesses (CWE)
References
- https://www.us-cert.gov/ics/advisories/icsa-20-135-01Third Party AdvisoryUS Government Resource
- https://www.us-cert.gov/ics/advisories/icsa-20-135-01Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2020-12042?
CVE-2020-12042 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. As a result, an attacker with user privileges can gain arbitr...
How severe is CVE-2020-12042?
CVE-2020-12042 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12042?
Check the references section above for vendor advisories and patch information. Affected products include: Opto22 Softpac Project.