CVE Vulnerabilities

CVE-2022-2336

Improper Authentication

Published: Aug 17, 2022 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as admin and password as admin. This allows Softing to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the admin password. There is no warning or prompt to ask the user to change the default password, and to change the password, many steps are required.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
EdgeaggregatorSofting3.1 (including)3.1 (including)
EdgeconnectorSofting3.1 (including)3.1 (including)
OpcSofting5.2 (including)5.2 (including)
Opc_ua_c++_software_development_kitSofting6 (including)6 (including)
Secure_integration_serverSofting1.22 (including)1.22 (including)
UagatesSofting1.74 (including)1.74 (including)

Potential Mitigations

References