An issue was discovered in Softing OPC UA C++ SDK before 6.10. A buffer overflow or an excess allocation happens due to unchecked array and matrix bounds in structure data types.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HSofting Edgeaggregator
APPSofting≤ 3.50Softing Edgeconnector
APPSofting≤ 3.50Softing Opc
APPSofting≤ 5.22Softing Opc Ua C\+\+ Software Development Kit
APPSofting≤ 6.00Softing Secure Integration Server
APPSofting≤ 1.22Softing Uagates
APPSofting≤ 1.74
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
Related vulnerabilities
CVE-2023-27335CRITICAL9.6PL ✓same product
Softing edgeAggregator: XSS umożliwiający RCE z uprawnieniami root
CVE-2022-2336CRITICAL9.8PL ✓same product
Softing — domyślne dane uwierzytelniające administratora (admin/admin)
CVE-2020-14524CRITICAL9.8PL ✓same product
Heap-based buffer overflow w Softing Industrial Automation umożliwiający RCE
CVE-2023-27334HIGH7.5same product
Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulne...
CVE-2023-27336HIGH7.5same product
Softing edgeConnector Siemens OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability. This vul...