Softing

Opc

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.45%
  • Veröffentlicht 14.12.2023 19:15:16
  • Zuletzt bearbeitet 22.05.2025 18:15:25

An uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may cause the application to crash when the server wants to send an error packet, while socket is blocked on writing.

  • EPSS 0.21%
  • Veröffentlicht 05.12.2023 06:15:48
  • Zuletzt bearbeitet 21.11.2024 08:11:58

Softing OPC Suite version 5.25 and before has Incorrect Access Control, allows attackers to obtain sensitive information via weak permissions in OSF_discovery service. The service executable could be changed or the service could be deleted.

  • EPSS 0.51%
  • Veröffentlicht 20.10.2022 21:15:10
  • Zuletzt bearbeitet 08.05.2025 19:15:52

An issue was discovered in Softing OPC UA C++ SDK 5.66 through 6.x before 6.10. An OPC/UA browse request exceeding the server limit on continuation points may cause a use-after-free error

  • EPSS 0.46%
  • Veröffentlicht 20.10.2022 21:15:10
  • Zuletzt bearbeitet 08.05.2025 19:15:52

An issue was discovered in Softing OPC UA C++ SDK before 6.10. A buffer overflow or an excess allocation happens due to unchecked array and matrix bounds in structure data types.

  • EPSS 0.99%
  • Veröffentlicht 17.08.2022 21:15:09
  • Zuletzt bearbeitet 21.11.2024 07:00:47

A crafted HTTP packet with a -1 content-length header can create a denial-of-service condition in Softing Secure Integration Server V1.22.

  • EPSS 0.73%
  • Veröffentlicht 17.08.2022 21:15:09
  • Zuletzt bearbeitet 21.11.2024 07:01:13

A crafted HTTP packet without a content-type header can create a denial-of-service condition in Softing Secure Integration Server V1.22.

  • EPSS 0.03%
  • Veröffentlicht 17.08.2022 21:15:09
  • Zuletzt bearbeitet 21.11.2024 07:00:47

Softing Secure Integration Server V1.22 is vulnerable to authentication bypass via a machine-in-the-middle attack. The default the administration interface is accessible via plaintext HTTP protocol, facilitating the attack. The HTTP request may conta...

  • EPSS 1.09%
  • Veröffentlicht 17.08.2022 21:15:09
  • Zuletzt bearbeitet 21.11.2024 07:00:47

A crafted HTTP packet with a missing HTTP URI can create a denial-of-service condition in Softing Secure Integration Server V1.22.

  • EPSS 0.24%
  • Veröffentlicht 17.08.2022 21:15:09
  • Zuletzt bearbeitet 21.11.2024 07:00:47

Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`. This allows Softing to log in to the server directly to perform administrative function...

  • EPSS 62.41%
  • Veröffentlicht 17.08.2022 21:15:08
  • Zuletzt bearbeitet 21.11.2024 07:00:47

The application searches for a library dll that is not found. If an attacker can place a dll with this name, then the attacker can leverage it to execute arbitrary code on the targeted Softing Secure Integration Server V1.22.