CVE Vulnerabilities

CVE-2022-2335

Integer Underflow (Wrap or Wraparound)

Published: Aug 17, 2022 | Modified: Aug 19, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A crafted HTTP packet with a -1 content-length header can create a denial-of-service condition in Softing Secure Integration Server V1.22.

Weakness

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Affected Software

Name Vendor Start Version End Version
Edgeaggregator Softing 3.1 (including) 3.1 (including)
Edgeconnector Softing 3.1 (including) 3.1 (including)
Opc Softing 5.2 (including) 5.2 (including)
Opc_ua_c++_software_development_kit Softing 6 (including) 6 (including)
Secure_integration_server Softing 1.22 (including) 1.22 (including)
Uagates Softing 1.74 (including) 1.74 (including)

References