Vulnerability Description
Softing OPC Suite version 5.25 and before has Incorrect Access Control, allows attackers to obtain sensitive information via weak permissions in OSF_discovery service. The service executable could be changed or the service could be deleted.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Softing | Opc | < 5.30 |
Related Weaknesses (CWE)
References
- https://industrial.softing.com/fileadmin/psirt/downloads/2023/syt-2023-5.htmlVendor Advisory
- https://industrial.softing.com/fileadmin/psirt/downloads/2023/syt-2023-5.htmlVendor Advisory
FAQ
What is CVE-2023-37572?
CVE-2023-37572 is a vulnerability with a CVSS score of 7.5 (HIGH). Softing OPC Suite version 5.25 and before has Incorrect Access Control, allows attackers to obtain sensitive information via weak permissions in OSF_discovery service. The service executable could be ...
How severe is CVE-2023-37572?
CVE-2023-37572 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-37572?
Check the references section above for vendor advisories and patch information. Affected products include: Softing Opc.