PT-2022-6555 · Softing · Softing Edgeaggregator+5
Sharon Brizinov
+2
·
Published
2022-05-10
·
Updated
2022-08-23
·
CVE-2022-1748
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Softing OPC UA C++ Server SDK (affected versions not specified)
Softing Secure Integration Server (affected versions not specified)
Softing edgeAggregator (affected versions not specified)
Softing edgeConnector (affected versions not specified)
Softing OPC Suite (affected versions not specified)
Softing uaGate (affected versions not specified)
Description
The issue is related to a NULL pointer dereference vulnerability in the implementation of OPC UA methods in Softing software. This vulnerability can be exploited by a remote attacker to cause a denial-of-service. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited. Technical details about exploitation include the
NULL pointer dereference vulnerability, which can be triggered by sending specific OPC UA messages.Recommendations
For Softing OPC UA C++ Server SDK, consider disabling the vulnerable
OPC UA functionality until a patch is available.
For Softing Secure Integration Server, restrict access to the server to minimize the risk of exploitation.
For Softing edgeAggregator, avoid using the affected edgeAggregator module in critical operations until the issue is resolved.
For Softing edgeConnector, temporarily disable the edgeConnector functionality to prevent potential exploitation.
For Softing OPC Suite, restrict access to the suite's OPC UA features to minimize the risk of exploitation.
For Softing uaGate, consider disabling the uaGate functionality until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Softing Opc Suite
Softing Opc Ua C++ Server Sdk
Softing Secure Integration Server
Softing Edgeaggregator
Softing Edgeconnector
Softing Uagate