Softing records
44 published records for vendor softing.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 4.5%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-476 NULL Pointer Dereference6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-552 Files or Directories Accessible to External Parties2
- CWE-400 Uncontrolled Resource Consumption2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-732 Incorrect Permission Assignment for Critical Resource2
The weakness classes this vendor ships most often: where to look.
CWEAll records
44 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
49Plan | CVE-2023-38126No exploit | Softing edgeAggregator Restore Configuration Directory Traversal Remote Code Execution Vulnerabilitysofting · edgeaggregator · CWE-22 | High7.2 | — | 71.2% | Dec 19, 2023 |
40Plan | CVE-2020-14524No exploit | Softing Industrial Automation OPCsofting · opc · CWE-122 | Critical9.8 | — | 2.5% | Aug 25, 2020 |
40Plan | CVE-2019-11526No exploit | An issue was discovered in Softing uaGate SI 1.60.01.softing · uagate si firmware · CWE-732 | Critical9.8 | — | 2.0% | Oct 10, 2019 |
39Monitor | CVE-2022-2336No exploit | Softing Secure Integration Server Improper Authenticationsofting · edgeaggregator · CWE-287 | Critical9.8 | — | 1.0% | Aug 17, 2022 |
38Monitor | CVE-2023-27335No exploit | Softing edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerabilitysofting · edgeaggregator · CWE-79 | Critical9.6 | — | 1.4% | May 2, 2024 |
36Monitor | CVE-2019-11527No exploit | An issue was discovered in Softing uaGate SI 1.60.01.softing · uagate si firmware · CWE-78 | High8.8 | — | 3.5% | Oct 10, 2019 |
36Monitor | CVE-2019-15051No exploit | An issue was discovered in Softing uaGate (SI, MB, 840D) firmware through 1.71.00.1225.softing · uagate si firmware · CWE-77 | High8.8 | — | 3.3% | Oct 10, 2019 |
35Monitor | CVE-2023-39479No exploit | Softing Secure Integration Server OPC UA Gateway Directory Creation Vulnerabilitysofting · secure integration server · CWE-552 | High8.8 | — | 1.6% | May 2, 2024 |
35Monitor | CVE-2023-39481No exploit | Softing Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerabilitysofting · secure integration server · CWE-436 | High8.8 | — | 1.6% | May 2, 2024 |
35Monitor | CVE-2023-39478No exploit | Softing Secure Integration Server Exposure of Resource to Wrong Sphere Remote Code Execution Vulnerabilitysofting · secure integration server · CWE-668 | High8.8 | — | 1.6% | May 2, 2024 |
35Monitor | CVE-2023-38125No exploit | Softing edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code Execution Vulnerabilitysofting · edgeaggregator · CWE-942 | High8.8 | — | 1.3% | May 2, 2024 |
35Monitor | CVE-2021-29660No exploit | A Cross-Site Request Forgery (CSRF) vulnerability in en/cfg_setpwd.html in Softing AG OPC Toolbox through 4.10.1.13035 allows attackers to rsofting · opc toolbox · CWE-352 | High8.8 | — | 0.6% | Apr 2, 2021 |
32Monitor | CVE-2022-1373Weaponized | Softing Secure Integration Server Relative Path Traversalsofting · edgeaggregator · CWE-23 | High7.2 | — | 12.8% | Aug 17, 2022 |
32Monitor | CVE-2022-2334Weaponized | Softing Secure Integration Server Uncontrolled Search Path Elementsofting · edgeaggregator · CWE-427 | High7.2 | — | 12.3% | Aug 17, 2022 |
31Monitor | CVE-2021-32994No exploit | Softing OPC-UA C++ SDK Improper Restriction of Operations within the Bounds of a Memory Buffersofting · opc ua c\+\+ software development kit · CWE-119 | High7.5 | — | 1.7% | Apr 4, 2022 |
30Monitor | CVE-2022-2335No exploit | Softing Secure Integration Server Integer Underflowsofting · edgeaggregator · CWE-191 | High7.5 | — | 1.5% | Aug 17, 2022 |
30Monitor | CVE-2022-1069No exploit | Softing Secure Integration Server Out-of-bounds Readsofting · edgeaggregator · CWE-125 | High7.5 | — | 1.5% | Aug 17, 2022 |
30Monitor | CVE-2021-40872No exploit | An issue was discovered in Softing Industrial Automation uaToolkit Embedded before 1.40.softing · smartlink hw-dp · CWE-843 | High7.5 | — | 1.5% | Nov 10, 2021 |
30Monitor | CVE-2022-2337No exploit | Softing Secure Integration Server NULL Pointer Dereferencesofting · edgeaggregator · CWE-476 | High7.5 | — | 1.5% | Aug 17, 2022 |
30Monitor | CVE-2022-2547No exploit | Softing Secure Integration Server NULL Pointer Dereferencesofting · edgeaggregator · CWE-476 | High7.5 | — | 1.5% | Aug 17, 2022 |
30Monitor | CVE-2020-14522No exploit | Softing Industrial Automation OPCsofting · opc · CWE-400 | High7.5 | — | 1.5% | Aug 25, 2020 |
30Monitor | CVE-2023-27334No exploit | Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerabilitysofting · edgeaggregator · CWE-400 | High7.5 | — | 1.4% | May 2, 2024 |
30Monitor | CVE-2021-40871No exploit | An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66.softing · datafeed opc suite · CWE-843 | High7.5 | — | 1.3% | Nov 10, 2021 |
30Monitor | CVE-2021-40873No exploit | An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40.softing · datafeed opc suite · CWE-415 | High7.5 | — | 1.3% | Nov 10, 2021 |
30Monitor | CVE-2019-11528No exploit | An issue was discovered in Softing uaGate SI 1.60.01.softing · uagate si firmware · CWE-732 | High7.5 | — | 1.2% | Oct 10, 2019 |
- CVE-2023-3812649Plan
Softing edgeAggregator Restore Configuration Directory Traversal Remote Code Execution Vulnerability
HighCVSS 7.2No exploitEPSS 71%softing · edgeaggregatorDec 19, 2023
- CVE-2020-1452440Plan
Softing Industrial Automation OPC
CriticalCVSS 9.8No exploitEPSS 3%softing · opcAug 25, 2020
- CVE-2019-1152640Plan
An issue was discovered in Softing uaGate SI 1.60.01.
CriticalCVSS 9.8No exploitEPSS 2%softing · uagate si firmwareOct 10, 2019
- CVE-2022-233639Monitor
Softing Secure Integration Server Improper Authentication
CriticalCVSS 9.8No exploitEPSS 1%softing · edgeaggregatorAug 17, 2022
- CVE-2023-2733538Monitor
Softing edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability
CriticalCVSS 9.6No exploitEPSS 1%softing · edgeaggregatorMay 2, 2024
- CVE-2019-1152736Monitor
An issue was discovered in Softing uaGate SI 1.60.01.
HighCVSS 8.8No exploitEPSS 3%softing · uagate si firmwareOct 10, 2019
- CVE-2019-1505136Monitor
An issue was discovered in Softing uaGate (SI, MB, 840D) firmware through 1.71.00.1225.
HighCVSS 8.8No exploitEPSS 3%softing · uagate si firmwareOct 10, 2019
- CVE-2023-3947935Monitor
Softing Secure Integration Server OPC UA Gateway Directory Creation Vulnerability
HighCVSS 8.8No exploitEPSS 2%softing · secure integration serverMay 2, 2024
- CVE-2023-3948135Monitor
Softing Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 2%softing · secure integration serverMay 2, 2024
- CVE-2023-3947835Monitor
Softing Secure Integration Server Exposure of Resource to Wrong Sphere Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 2%softing · secure integration serverMay 2, 2024
- CVE-2023-3812535Monitor
Softing edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%softing · edgeaggregatorMay 2, 2024
- CVE-2021-2966035Monitor
A Cross-Site Request Forgery (CSRF) vulnerability in en/cfg_setpwd.html in Softing AG OPC Toolbox through 4.10.1.13035 allows attackers to r
HighCVSS 8.8No exploitEPSS 1%softing · opc toolboxApr 2, 2021
- CVE-2022-137332Monitor
Softing Secure Integration Server Relative Path Traversal
HighCVSS 7.2WeaponizedEPSS 13%softing · edgeaggregatorAug 17, 2022
- CVE-2022-233432Monitor
Softing Secure Integration Server Uncontrolled Search Path Element
HighCVSS 7.2WeaponizedEPSS 12%softing · edgeaggregatorAug 17, 2022
- CVE-2021-3299431Monitor
Softing OPC-UA C++ SDK Improper Restriction of Operations within the Bounds of a Memory Buffer
HighCVSS 7.5No exploitEPSS 2%softing · opc ua c\+\+ software development kitApr 4, 2022
- CVE-2022-233530Monitor
Softing Secure Integration Server Integer Underflow
HighCVSS 7.5No exploitEPSS 2%softing · edgeaggregatorAug 17, 2022
- CVE-2022-106930Monitor
Softing Secure Integration Server Out-of-bounds Read
HighCVSS 7.5No exploitEPSS 2%softing · edgeaggregatorAug 17, 2022
- CVE-2021-4087230Monitor
An issue was discovered in Softing Industrial Automation uaToolkit Embedded before 1.40.
HighCVSS 7.5No exploitEPSS 2%softing · smartlink hw-dpNov 10, 2021
- CVE-2022-233730Monitor
Softing Secure Integration Server NULL Pointer Dereference
HighCVSS 7.5No exploitEPSS 1%softing · edgeaggregatorAug 17, 2022
- CVE-2022-254730Monitor
Softing Secure Integration Server NULL Pointer Dereference
HighCVSS 7.5No exploitEPSS 1%softing · edgeaggregatorAug 17, 2022
- CVE-2020-1452230Monitor
Softing Industrial Automation OPC
HighCVSS 7.5No exploitEPSS 1%softing · opcAug 25, 2020
- CVE-2023-2733430Monitor
Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability
HighCVSS 7.5No exploitEPSS 1%softing · edgeaggregatorMay 2, 2024
- CVE-2021-4087130Monitor
An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66.
HighCVSS 7.5No exploitEPSS 1%softing · datafeed opc suiteNov 10, 2021
- CVE-2021-4087330Monitor
An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40.
HighCVSS 7.5No exploitEPSS 1%softing · datafeed opc suiteNov 10, 2021
- CVE-2019-1152830Monitor
An issue was discovered in Softing uaGate SI 1.60.01.
HighCVSS 7.5No exploitEPSS 1%softing · uagate si firmwareOct 10, 2019