Security Advisory

CVE-2020-12042

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-05-14 20:28:03
Last updated 2024-08-04 11:48:57
Assigner icscert
CVSS score not scored
State PUBLISHED

Description

Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. As a result, an attacker with user privileges can gain arbitrary file write access with system access.