CVE-2023-41151
- EPSS 0.45%
- Veröffentlicht 14.12.2023 19:15:16
- Zuletzt bearbeitet 22.05.2025 18:15:25
An uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may cause the application to crash when the server wants to send an error packet, while socket is blocked on writing.
CVE-2023-37572
- EPSS 0.21%
- Veröffentlicht 05.12.2023 06:15:48
- Zuletzt bearbeitet 21.11.2024 08:11:58
Softing OPC Suite version 5.25 and before has Incorrect Access Control, allows attackers to obtain sensitive information via weak permissions in OSF_discovery service. The service executable could be changed or the service could be deleted.
CVE-2022-39823
- EPSS 0.51%
- Veröffentlicht 20.10.2022 21:15:10
- Zuletzt bearbeitet 08.05.2025 19:15:52
An issue was discovered in Softing OPC UA C++ SDK 5.66 through 6.x before 6.10. An OPC/UA browse request exceeding the server limit on continuation points may cause a use-after-free error
CVE-2022-37453
- EPSS 0.46%
- Veröffentlicht 20.10.2022 21:15:10
- Zuletzt bearbeitet 08.05.2025 19:15:52
An issue was discovered in Softing OPC UA C++ SDK before 6.10. A buffer overflow or an excess allocation happens due to unchecked array and matrix bounds in structure data types.
CVE-2022-2335
- EPSS 0.99%
- Veröffentlicht 17.08.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 07:00:47
A crafted HTTP packet with a -1 content-length header can create a denial-of-service condition in Softing Secure Integration Server V1.22.
CVE-2022-2547
- EPSS 0.73%
- Veröffentlicht 17.08.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 07:01:13
A crafted HTTP packet without a content-type header can create a denial-of-service condition in Softing Secure Integration Server V1.22.
CVE-2022-2338
- EPSS 0.03%
- Veröffentlicht 17.08.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 07:00:47
Softing Secure Integration Server V1.22 is vulnerable to authentication bypass via a machine-in-the-middle attack. The default the administration interface is accessible via plaintext HTTP protocol, facilitating the attack. The HTTP request may conta...
CVE-2022-2337
- EPSS 1.09%
- Veröffentlicht 17.08.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 07:00:47
A crafted HTTP packet with a missing HTTP URI can create a denial-of-service condition in Softing Secure Integration Server V1.22.
CVE-2022-2336
- EPSS 0.24%
- Veröffentlicht 17.08.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 07:00:47
Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`. This allows Softing to log in to the server directly to perform administrative function...
CVE-2022-2334
- EPSS 62.41%
- Veröffentlicht 17.08.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:47
The application searches for a library dll that is not found. If an attacker can place a dll with this name, then the attacker can leverage it to execute arbitrary code on the targeted Softing Secure Integration Server V1.22.