ZeroHour

Vulnerabilities

43 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-27335
+4 in the same advisory: …38125 …27334 …27336 …39482
Softing edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability.

Softing edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the input parameters provided to the edgeAggregetor client. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-20504.

NVD description · AI analysis pending
9.6
group max
1%
  • softing edgeaggregator
  • softing secure integration server
CVE-2023-39481
+3 in the same advisory: …39479 …39478 …39480
Softing Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerability.

Softing Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing Secure Integration Server. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the web server. The issue results from an inconsistency in URI parsing between NGINX and application code. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-20551.

NVD description · AI analysis pending
8.8
group max
2%
  • softing secure integration server
CVE-2024-0860
The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker to capture packets to craft t

The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker to capture packets to craft their own requests.

NVD description · AI analysis pending
7.5<1%
  • softing edgeaggregator
  • softing edgeconnector
CVE-2023-37571
Softing TH SCOPE through 3.70 allows XSS.

Softing TH SCOPE through 3.70 allows XSS.

NVD description · AI analysis pending
6.1<1%
  • softing th scope
CVE-2023-38126
Softing edgeAggregator Restore Configuration Directory Traversal Remote Code Execution Vulnerability.

Softing edgeAggregator Restore Configuration Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of backup zip files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this to execute code in the context of root. Was ZDI-CAN-20543.

NVD description · AI analysis pending
7.271%
  • softing edgeaggregator
CVE-2023-41151
An uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may cause the application to crash when the server wan

An uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may cause the application to crash when the server wants to send an error packet, while socket is blocked on writing.

NVD description · AI analysis pending
7.5<1%
  • softing opc
  • softing opc ua c\+\+ software development kit
  • softing secure integration server
CVE-2023-37572
Softing OPC Suite version 5.25 and before has Incorrect Access Control, allows attackers to obtain sensitive information via weak permissions in OSF_discovery s

Softing OPC Suite version 5.25 and before has Incorrect Access Control, allows attackers to obtain sensitive information via weak permissions in OSF_discovery service. The service executable could be changed or the service could be deleted.

NVD description · AI analysis pending
7.5<1%
  • softing opc
CVE-2022-48193
+1 in the same advisory: …48192
Weak ciphers in Softing smartLink SW-HT before 1.30 are enabled during secure communication (SSL).

Weak ciphers in Softing smartLink SW-HT before 1.30 are enabled during secure communication (SSL).

NVD description · AI analysis pending
7.5
group max
<1%
  • softing smartlink sw-ht
CVE-2022-45920
+1 in the same advisory: …44018
In Softing uaToolkit Embedded before 1.41, a malformed CreateMonitoredItems request may cause a memory leak.

In Softing uaToolkit Embedded before 1.41, a malformed CreateMonitoredItems request may cause a memory leak.

NVD description · AI analysis pending
7.5<1%
  • softing uatoolkit embedded
CVE-2022-39823
An issue was discovered in Softing OPC UA C++ SDK 5.66 through 6.x before 6.10.

An issue was discovered in Softing OPC UA C++ SDK 5.66 through 6.x before 6.10. An OPC/UA browse request exceeding the server limit on continuation points may cause a use-after-free error

NVD description · AI analysis pending
7.5<1%
  • softing opc
  • softing opc ua c\+\+ software development kit
CVE-2022-37453
An issue was discovered in Softing OPC UA C++ SDK before 6.10.

An issue was discovered in Softing OPC UA C++ SDK before 6.10. A buffer overflow or an excess allocation happens due to unchecked array and matrix bounds in structure data types.

NVD description · AI analysis pending
7.5<1%
  • softing edgeaggregator
  • softing edgeconnector
  • softing opc
  • +1 more
CVE-2022-2336
Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin

Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`. This allows Softing to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the `admin` password. There is no warning or prompt to ask the user to change the default password, and to change the password, many steps are required.

NVD description · AI analysis pending
9.8
group max
<1%
  • softing edgeaggregator
  • softing edgeconnector
  • softing opc
  • +1 more
CVE-2021-32994
Softing OPC UA C++ SDK (Software Development Kit) versions from 5.59 to 5.64 exported library functions don't properly validate received extension objects, whic

Softing OPC UA C++ SDK (Software Development Kit) versions from 5.59 to 5.64 exported library functions don't properly validate received extension objects, which may allow an attacker to crash the software by sending a variety of specially crafted packets to access several unexpected memory locations.

NVD description · AI analysis pending
7.52%
  • softing opc ua c\+\+ software development kit
CVE-2021-42577
+1 in the same advisory: …42262
An issue was discovered in Softing OPC UA C++ SDK before 5.70.

An issue was discovered in Softing OPC UA C++ SDK before 5.70. A malformed OPC/UA message abort packet makes the client crash with a NULL pointer dereference.

NVD description · AI analysis pending
7.5
group max
<1%
  • softing datafeed opc suite
  • softing opc ua c\+\+ software development kit
  • softing secure integration server
CVE-2021-40873
+1 in the same advisory: …40871
An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40.

An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a client or server. The server process may crash unexpectedly because of a double free, and must be restarted.

NVD description · AI analysis pending
7.51%
  • softing datafeed opc suite
  • softing edgeconnector
  • softing opc
  • +1 more
CVE-2021-40872
An issue was discovered in Softing Industrial Automation uaToolkit Embedded before 1.40.

An issue was discovered in Softing Industrial Automation uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) or login as an anonymous user (bypassing security checks) by sending crafted messages to a OPC/UA server. The server process may crash unexpectedly because of an invalid type cast, and must be restarted.

NVD description · AI analysis pending
7.52%
  • softing smartlink hw-dp
  • softing uatoolkit embedded
CVE-2021-29660
+1 in the same advisory: …29661
A Cross-Site Request Forgery (CSRF) vulnerability in en/cfg_setpwd.html in Softing AG OPC Toolbox through 4.10.1.13035 allows attackers to reset the administrat

A Cross-Site Request Forgery (CSRF) vulnerability in en/cfg_setpwd.html in Softing AG OPC Toolbox through 4.10.1.13035 allows attackers to reset the administrative password by inducing the Administrator user to browse a URL controlled by an attacker.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • softing opc toolbox
CVE-2020-14524
+1 in the same advisory: …14522
Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to a heap-based buffer overflow, whic

Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.

NVD description · AI analysis pending
9.8
group max
3%
  • softing opc
CVE-2019-11526
+3 in the same advisory: …11527 …15051 …11528
An issue was discovered in Softing uaGate SI 1.60.01.

An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable to file path injection. This enables the Attacker to write files with superuser privileges in specific locations.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • softing uagate si firmware