MEDIUM · 5.7

CVE-2022-2338

Softing Secure Integration Server V1.22 is vulnerable to authentication bypass via a machine-in-the-middle attack. The default the administration interface is accessible via plaintext HTTP protocol, f...

Vulnerability Description

Softing Secure Integration Server V1.22 is vulnerable to authentication bypass via a machine-in-the-middle attack. The default the administration interface is accessible via plaintext HTTP protocol, facilitating the attack. The HTTP request may contain the session cookie in the request, which may be captured for use in authenticating to the server.

CVSS Score

5.7

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
SoftingEdgeaggregator3.1
SoftingEdgeconnector3.1
SoftingOpc5.2
SoftingOpc Ua C\+\+ Software Development Kit6
SoftingSecure Integration Server1.22
SoftingUagates1.74

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-2338?

CVE-2022-2338 is a vulnerability with a CVSS score of 5.7 (MEDIUM). Softing Secure Integration Server V1.22 is vulnerable to authentication bypass via a machine-in-the-middle attack. The default the administration interface is accessible via plaintext HTTP protocol, f...

How severe is CVE-2022-2338?

CVE-2022-2338 has been rated MEDIUM with a CVSS base score of 5.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-2338?

Check the references section above for vendor advisories and patch information. Affected products include: Softing Edgeaggregator, Softing Edgeconnector, Softing Opc, Softing Opc Ua C\+\+ Software Development Kit, Softing Secure Integration Server.