Improper access control in PAC Project Basic and PAC Project Professional - CVE-2020-10612

 

Improper access control in PAC Project Basic and PAC Project Professional - CVE-2020-10612

Published: May 15, 2020


Vulnerability identifier: #VU27945
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10612
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to the SoftPACAgent communicates with SoftPACMonitor over network Port 22000 without any restrictions. A remote attacker can control the SoftPACAgent service including updating SoftPAC firmware, starting or stopping service, or writing to certain registry values.


Affected software

PAC Project Basic
PAC Project Professional

How to mitigate CVE-2020-10612

Install updates from vendor's website.

PAC Project Basic - update to 10.3
PAC Project Professional - update to 10.3

External References

Related Security Bulletins