CVE Vulnerabilities

CVE-2022-2336

Improper Authentication

Published: Aug 17, 2022 | Modified: Aug 22, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as admin and password as admin. This allows Softing to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the admin password. There is no warning or prompt to ask the user to change the default password, and to change the password, many steps are required.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Edgeaggregator Softing 3.1 3.1
Secure_integration_server Softing 1.22 1.22
Edgeconnector Softing 3.1 3.1
Opc Softing 5.2 5.2
Opc_ua_c++_software_development_kit Softing 6 6
Uagates Softing 1.74 1.74

Potential Mitigations

References