SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2023-29377

MEDIUM · CVSS 6.6 EPSS 0.48%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Softing OPC UA C++ SDK versions up to 6.20 and Softing Secure Integration Server up to 1.22 are vulnerable to a directory path assignment bypass due to improper handling of FileType renames. This vulnerability could allow an attacker to manipulate file paths, potentially leading to unauthorized access or data exposure. Organizations using these products should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2023-29377
Severity
MEDIUM
CVSS
6.6
EPSS
0.48%

Original NVD Description

An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is possible to bypass limitations on assignment of a directory path to FileDirectory OPC UA objects and a file path to File OPC UA objects.