Known Vulnerabilities for products from Softing

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Softing".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2024-14028 Not Provided 2026-03-27 2026-03-27
CVE-2023-37572 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 7.5 - HIGH 2023-12-05 2024-01-25
CVE-2023-37571 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 6.1 - MEDIUM 2024-01-30 2024-02-05
CVE-2023-7339 Not Provided 2026-03-27 2026-03-27
CVE-2022-48193 Weak ciphers in Softing smartLink SW-HT before 1.30 are enabled during secure communication (SSL). 7.5 - HIGH 2023-11-06 2023-11-14
CVE-2022-48192 Cross-site Scripting vulnerability in Softing smartLink SW-HT before 1.30, which allows an attacker to execute a dynamic scri... 6.1 - MEDIUM 2023-11-06 2023-11-14
CVE-2022-45920 In Softing uaToolkit Embedded before 1.41, a malformed CreateMonitoredItems request may cause a memory leak. 7.5 - HIGH 2023-01-26 2023-02-01
CVE-2022-44018 In Softing uaToolkit Embedded before 1.40.1, a malformed PubSub discovery announcement message can cause a NULL pointer deref... 7.5 - HIGH 2023-01-26 2023-02-01
CVE-2022-39823 An issue was discovered in Softing OPC UA C++ SDK 5.66 through 6.x before 6.10. An OPC/UA browse request exceeding the server... 7.5 - HIGH 2022-10-20 2022-10-25
CVE-2022-37453 An issue was discovered in Softing OPC UA C++ SDK before 6.10. A buffer overflow or an excess allocation happens due to unche... 7.5 - HIGH 2022-10-20 2022-10-25
CVE-2022-2547 A crafted HTTP packet without a content-type header can create a denial-of-service condition in Softing Secure Integration Se... 7.5 - HIGH 2022-08-17 2022-08-19
CVE-2022-2338 Softing Secure Integration Server V1.22 is vulnerable to authentication bypass via a machine-in-the-middle attack. The defaul... 5.3 - MEDIUM 2022-08-17 2022-08-19
CVE-2022-2337 A crafted HTTP packet with a missing HTTP URI can create a denial-of-service condition in Softing Secure Integration Server V... 7.5 - HIGH 2022-08-17 2022-08-19
CVE-2022-2336 Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credential... 9.8 - CRITICAL 2022-08-17 2022-08-22
CVE-2022-2335 A crafted HTTP packet with a -1 content-length header can create a denial-of-service condition in Softing Secure Integration ... 7.5 - HIGH 2022-08-17 2022-08-19
CVE-2022-2334 The application searches for a library dll that is not found. If an attacker can place a dll with this name, then the attacke... 7.2 - HIGH 2022-08-17 2022-08-19
CVE-2022-1748 Softing OPC UA C++ Server SDK, Secure Integration Server, edgeConnector, edgeAggregator, OPC Suite, and uaGate are affected b... 7.5 - HIGH 2022-08-17 2022-08-19
CVE-2022-1373 The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vul... 7.2 - HIGH 2022-08-17 2023-06-27
CVE-2022-1069 A crafted HTTP packet with a large content-length header can create a denial-of-service condition in Softing Secure Integrati... 7.5 - HIGH 2022-08-17 2022-08-19
CVE-2021-42577 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 7.5 - HIGH 2022-03-11 2022-03-18

Known software with vulnerabilities from Softing

Type Vendor Product Version
ApplicationSoftingOpc4.20.00
Operating
System
SoftingUagate Si Firmware1.60.01