Security Advisory

CVE-2020-12042

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-05-14 20:28:03
Last updated 2024-08-04 11:48:57
Assigner icscert
State PUBLISHED

Description

Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. As a result, an attacker with user privileges can gain arbitrary file write access with system access.