Vulnerability Details CVE-2022-1373
The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. An attacker can craft a zip file to load an arbitrary dll and execute code. Using the "restore configuration" feature to upload a zip file containing a path traversal file may cause a file to be created and executed upon touching the disk.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.693
EPSS Ranking 98.5%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2022-1373
-
cpe:2.3:a:softing:edgeaggregator:3.1
-
cpe:2.3:a:softing:edgeconnector:3.1
-
cpe:2.3:a:softing:opc:5.2
-
cpe:2.3:a:softing:opc_ua_c++_software_development_kit:6
-
cpe:2.3:a:softing:secure_integration_server:1.22
-
cpe:2.3:a:softing:uagates:1.74