CVE-2020-10620 is a critical vulnerability affecting Opto 22 SoftPAC Project versions 9.6 and prior. It stems from a lack of credential-based communication, allowing any attacker with network access to directly interact with SoftPAC, including remotely stopping the service. With a CVSS score of 9.8 (Critical), this vulnerability is easily exploitable over the network with low attack complexity, leading to high impacts on confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered significant community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.6CPE matchmatch criteria | cpe:2.3:a:opto22:softpac_project:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.