Firmware Signature Verification Bypass in Opto 22 SoftPAC Project

Firmware Signature Verification Bypass in Opto 22 SoftPAC Project

CVE-2020-12046 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N

Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC’s firmware files’ signatures are not verified upon firmware update. This allows an attacker to replace legitimate firmware files with malicious files.

Learn more about our Web Application Penetration Testing UK.