Softpac Project
Vendor:
First CVE: May 14, 2020 · Active for 6 years
5
Total CVEs
More Total CVEs than 79% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 72% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Softpac Project over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 14, 2020
6 years ago
Most Recent CVE
May 14, 2020
2,266 days ago
CVE Severity & Scoring
Softpac Project5 CVEs
40%
20%
40%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (60.0%)
Unknown0 (0.0%)
Required2 (40.0%)
Privileges Required
Low2 (40.0%)
High0 (0.0%)
None3 (60.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-10620CRITICAL Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to directly communicate with Soft | May 14, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-10612CRITICAL Opto 22 SoftPAC Project Version 9.6 and prior. SoftPACAgent communicates with SoftPACMonitor over network Port 22000. However, this port is open without any restrictions. This allo | May 14, 2020 | 9.1 | 28 | NO | NO |
CVE-2020-10616HIGH Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC does not specify the path of multiple imported .dll files. Therefore, an attacker can replace them and execute code whenever | May 14, 2020 | 8.8 | 22 | NO | NO |
CVE-2020-12042MEDIUM Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. As a result, an attacker with user privil | May 14, 2020 | 6.5 | 17 | NO | NO |
CVE-2020-12046MEDIUM Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC’s firmware files’ signatures are not verified upon firmware update. This allows an attacker to replace legitimate firmware fi | May 14, 2020 | 5.7 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Softpac Project
Top CWEs
Versions
No cataloged versions.