Opto 22 SoftPAC Project
Opto 22 SoftPAC Project version 9.6 and earlier contain multiple vulnerabilities affecting file write operations (CWE-73), digital signature verification (CWE-347), authorization checks (CWE-284, CWE-285), and code integrity (CWE-427). These flaws allow unauthenticated remote attackers to achieve arbitrary file write with system privileges, remotely execute code, start or stop services, and degrade system availability. The vulnerabilities are exploitable over the network on port 22000 without user interaction.
- Network access to port 22000 on the SoftPAC Project system
- SoftPAC Project version 9.6 or earlier running
Patching may require device reboot — plan for process interruption
/api/v1/advisories/291f75db-0495-4165-a713-7d7992fe47a7Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.