Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSofting Opc
APPSofting< 4.47.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
Related vulnerabilities
CVE-2022-2336CRITICAL9.8PL ✓same product
Softing — domyślne dane uwierzytelniające administratora (admin/admin)
CVE-2023-41151HIGH7.5same product
An uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may ...
CVE-2023-37572HIGH7.5same product
Softing OPC Suite version 5.25 and before has Incorrect Access Control, allows attackers to obtain sensitive i...
CVE-2022-37453HIGH7.5same product
An issue was discovered in Softing OPC UA C++ SDK before 6.10. A buffer overflow or an excess allocation happe...
CVE-2022-39823HIGH7.5same product
An issue was discovered in Softing OPC UA C++ SDK 5.66 through 6.x before 6.10. An OPC/UA browse request excee...