{"api_version":"1","generated_at":"2026-07-23T09:43:46+00:00","cve":"CVE-2020-10620","urls":{"html":"https://cve.report/CVE-2020-10620","api":"https://cve.report/api/cve/CVE-2020-10620.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-10620","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-10620"},"summary":{"title":"CVE-2020-10620","description":"Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to directly communicate with SoftPAC, including, for example, stopping the service remotely.","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2020-05-14 21:15:00","updated_at":"2020-05-18 13:15:00"},"problem_types":["CWE-862"],"metrics":[],"references":[{"url":"https://www.us-cert.gov/ics/advisories/icsa-20-135-01","name":"https://www.us-cert.gov/ics/advisories/icsa-20-135-01","refsource":"MISC","tags":["Third Party Advisory","US Government Resource"],"title":"Opto 22 SoftPAC Project | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-10620","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-10620","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"10620","vulnerable":"1","versionEndIncluding":"9.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"opto22","cpe5":"softpac_project","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2020-10620","ASSIGNER":"ics-cert@hq.dhs.gov","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"Opto 22 SoftPAC Project","version":{"version_data":[{"version_value":"SoftPAC Project Version 9.6 and prior"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"IMPROPER AUTHORIZATION CWE-285"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://www.us-cert.gov/ics/advisories/icsa-20-135-01","url":"https://www.us-cert.gov/ics/advisories/icsa-20-135-01"}]},"description":{"description_data":[{"lang":"eng","value":"Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to directly communicate with SoftPAC, including, for example, stopping the service remotely."}]}},"nvd":{"publishedDate":"2020-05-14 21:15:00","lastModifiedDate":"2020-05-18 13:15:00","problem_types":["CWE-862"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:opto22:softpac_project:*:*:*:*:*:*:*:*","versionEndIncluding":"9.6","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"10620","Ordinal":"171039","Title":"CVE-2020-10620","CVE":"CVE-2020-10620","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"10620","Ordinal":"1","NoteData":"Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to directly communicate with SoftPAC, including, for example, stopping the service remotely.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"10620","Ordinal":"2","NoteData":"2020-05-14","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"10620","Ordinal":"3","NoteData":"2020-05-14","Type":"Other","Title":"Modified"}]}}}