CVE Vulnerabilities

CVE-2022-1748

NULL Pointer Dereference

Published: Aug 17, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Softing OPC UA C++ Server SDK, Secure Integration Server, edgeConnector, edgeAggregator, OPC Suite, and uaGate are affected by a NULL pointer dereference vulnerability.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Edgeaggregator Softing 3.1 (including) 3.1 (including)
Edgeconnector Softing 3.1 (including) 3.1 (including)
Opc Softing 5.2 (including) 5.2 (including)
Opc_ua_c++_software_development_kit Softing 6 (including) 6 (including)
Secure_integration_server Softing 1.22 (including) 1.22 (including)
Uagates Softing 1.74 (including) 1.74 (including)

Potential Mitigations

References