
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability (CVE-2020-12042) affects Opto 22 SoftPAC Project Version 9.6 and prior versions. The vulnerability involves unsanitized paths within zip files used for SoftPAC firmware updates. This security flaw was discovered and disclosed on May 14, 2020 (CISA Advisory, NVD).
The vulnerability stems from improper path sanitization within zip files used for firmware updates. It has been assigned a CVSS v3.1 base score of 6.5 (Medium) with the vector string AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N. The vulnerability is classified under CWE-347 (Improper Verification of Cryptographic Signature) (CISA Advisory).
When exploited, this vulnerability allows an attacker with user privileges to gain arbitrary file write access with system access. This could potentially lead to unauthorized system modifications and compromise of system integrity (CISA Advisory).
The vulnerability requires low attack complexity and can be exploited remotely. The attacker needs low privileges and no user interaction for successful exploitation. No known public exploits specifically targeting this vulnerability have been reported (CISA Advisory).
Opto 22 has released PAC Project 10.3 as a fix for this vulnerability. Users are recommended to upgrade to this version. Additionally, CISA recommends implementing defensive measures including monitoring or restricting Port 22000 at the firewall, minimizing network exposure for control system devices, and ensuring systems are not accessible from the Internet (CISA Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."