QID 591147

Date Published: 2022-11-07

QID 591147: Softing Secure Integration Server Multiple Vulnerabilities (ICSA-22-228-04)

Softing Secure Integration Server is found to be affected with multiple security vulnerabilities

AFFECTED PRODUCTS
The following products and versions are affected:
Secure Integration Server: Version 1.22 and prior
OPC UA C++ Server SDK: Version 6

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys.

Successful exploitation of these vulnerabilities could result in denial-of-service and arbitrary code execution which may aid further attacks.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-22-228-04 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ICSA-22-228-04 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-228-04