Skip to main content

Vendor archive

opto22 CVEs

Beta · best-effort

13 CVEs tagged to vendor opto224 Critical, 4 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2020-12046

Published May 14, 2020

Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC’s firmware files’ signatures are not verified upon firmware update. This allows an attacker to replace legitimate firmware f…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12042

Published May 14, 2020

Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. As a result, an attacker with user privi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10620

Published May 14, 2020

Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to directly communicate with Sof…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-10616

Published May 14, 2020

Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC does not specify the path of multiple imported .dll files. Therefore, an attacker can replace them and execute code whenever…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10612

Published May 14, 2020

Opto 22 SoftPAC Project Version 9.6 and prior. SoftPACAgent communicates with SoftPACMonitor over network Port 22000. However, this port is open without any restrictions. This all…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-14807

Published Oct 18, 2018

A stack-based buffer overflow vulnerability in Opto 22 PAC Control Basic and PAC Control Professional versions R10.0a and prior may allow remote code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1