← Back to CVE List
CVE-2023-29377NVD
Description
An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is possible to bypass limitations on assignment of a directory path to FileDirectory OPC UA objects and a file path to File OPC UA objects.
CVSS Base Metrics
CVSS v3 (3.1)
MEDIUM 6.6
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-23 - CWE-23 Relative Path Traversal
Affected & Patched Versions
| Product | Affected Versions | Patched Version |
|---|---|---|
| Softing Secure Integration Server | 0 - <= 1.22 | N/A |