CVSS v3
7.2
HIGH
EPSS Score
68.6%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. An attacker can craft a zip file to load an arbitrary dll and execute code. Using the "restore configuration" feature to upload a zip file containing a path traversal file may cause a file to be created and executed upon touching the disk.
The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. An attacker can craft a zip file to load an arbitrary dll and execute code. Using the "restore configuration" feature to upload a zip file containing a path traversal file may cause a file to be created and executed upon touching the disk.
Active exploitation of CVE-2022-1373 has not been confirmed. The EPSS score is 68.6%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2022-1373 has a CVSS v3 base score of 7.2 (HIGH severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).