CRITICAL🇵🇱 Wersja polska

CVE-2023-27335

CVSS 9.6v3.1pub. 2024-05-03upd. 2025-08-13

Softing edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the input parameters provided to the edgeAggregetor client. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-20504.

🤖 AI Analysis
How it works

The vulnerability results from insufficient validation of user-supplied data in the input parameters of the edgeAggregator client. The lack of this validation allows injection of arbitrary scripts (XSS). For the exploit to work, the victim must visit a malicious website or open a malicious file. The attacker can then exploit this vulnerability in combination with other flaws to achieve arbitrary code execution with root privileges.

Impact

An attacker can execute arbitrary code in the context of the root user on the attacked system, which means complete takeover of the device, including the ability to compromise confidentiality, integrity, and availability of data.

Mitigation & patch

Patches available from the vendor should be applied in accordance with the references. Detailed information is available in the Zero Day Initiative advisory at https://www.zerodayinitiative.com/advisories/ZDI-23-1057/

Who is affected

Softing edgeAggregator and Softing Secure Integration Server — versions indicated in the vendor references and ZDI-23-1057 advisory

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Softing Edgeaggregator

    APP
    Softing
    < 3.70
  • Softing Secure Integration Server

    APP
    Softing
    < 1.30
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEXSS
CWE
References

Related vulnerabilities

CVE-2022-2336CRITICAL9.8PL ✓same product

Softing — domyślne dane uwierzytelniające administratora (admin/admin)

CVE-2023-27336HIGH7.5same product

Softing edgeConnector Siemens OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability. This vul...

CVE-2023-38125HIGH8.8same product

Softing edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code Execution Vulnerabili...

CVE-2023-27334HIGH7.5same product

Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulne...

CVE-2023-39478HIGH8.8same product

Softing Secure Integration Server Exposure of Resource to Wrong Sphere Remote Code Execution Vulnerability. Th...