Skip to main content

Vendor archive

softing CVEs

Beta · best-effort

44 CVEs tagged to vendor softing4 Critical, 32 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2023-39481

Published May 3, 2024

Softing Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected ins…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39480

Published May 3, 2024

Softing Secure Integration Server FileDirectory OPC UA Object Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affect…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39479

Published May 3, 2024

Softing Secure Integration Server OPC UA Gateway Directory Creation Vulnerability. This vulnerability allows remote attackers to create directories on affected installations of So…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39478

Published May 3, 2024

Softing Secure Integration Server Exposure of Resource to Wrong Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38126

Published Dec 19, 2023

Softing edgeAggregator Restore Configuration Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affec…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37572

Published Dec 5, 2023

Softing OPC Suite version 5.25 and before has Incorrect Access Control, allows attackers to obtain sensitive information via weak permissions in OSF_discovery service. The service…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-48192

Published Nov 6, 2023

Cross-site Scripting vulnerability in Softing smartLink SW-HT before 1.30, which allows an attacker to execute a dynamic script (JavaScript, VBScript) in the context of the applic…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-44018

Published Jan 26, 2023

In Softing uaToolkit Embedded before 1.40.1, a malformed PubSub discovery announcement message can cause a NULL pointer dereference or out-of-bounds memory access in the subscribe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 44 CVEsPage 1 of 2