<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T22:43:04.545039+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-29559</id>
    <title>cnvd-2020-29559</title>
    <updated>2026-10-03T22:43:04.619775+00:00</updated>
    <content>cnvd-2020-29559</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-29559"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-39946</id>
    <title>EUVD-2026-39946</title>
    <updated>2026-10-03T22:43:04.619812+00:00</updated>
    <content>EUVD-2026-39946</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-39946"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-10620</id>
    <title>fkie_cve-2020-10620</title>
    <updated>2026-10-03T22:43:04.619828+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to directly communicate with SoftPAC, including, for example, stopping the service remotely.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-10620"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-72jg-wqh4-qw67</id>
    <title>GHSA-72jg-wqh4-qw67</title>
    <updated>2026-10-03T22:43:04.619859+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to directly communicate with SoftPAC, including, for example, stopping the service remotely.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-72jg-wqh4-qw67"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-10620</id>
    <title>gsd-2020-10620</title>
    <updated>2026-10-03T22:43:04.619875+00:00</updated>
    <content>gsd-2020-10620</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-10620"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-20-135-01</id>
    <title>ICSA-20-135-01 — Opto 22 SoftPAC Project</title>
    <updated>2026-10-03T22:43:04.619886+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. As a result, an attacker with user privileges can gain arbitrary file write access with system access.CVE-2020-12042 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N). SoftPAC 's firmware files ' signatures are not verified upon firmware update. This allows an attacker to replace legitimate firmware files with malicious files.CVE-2020-12046 has been assigned to this vulnerability. A CVSS v3 base score of 5.7 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N). SoftPACAgent communicates with SoftPACMonitor over network Port 22000. However, this port is open without any restrictions. This allows an attacker with network access to control the SoftPACAgent service including updating SoftPAC firmware, starting or stopping service, or writing to certain registry values.CVE-2020-10612 has been assigned to this vulnerability. A CVSS v3 base score of 9.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H). SoftPAC does not specify the path of multiple imported .dll files. Therefore, an attacker can replace them and execute code whenever the service starts.CVE-2020-10616 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N). Soft…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-20-135-01"/>
  </entry>
</feed>
