CVE-2020-12042

Publication date

2020-05-14 20:28:03

Family

icscert

State

PUBLISHED

Description

Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. As a result, an attacker with user privileges can gain arbitrary file write access with system access.