TROYANOSYVIRUS
Retour aux CVEs

CVE-2022-2338

MEDIUM
5.7

Description

Softing Secure Integration Server V1.22 is vulnerable to authentication bypass via a machine-in-the-middle attack. The default the administration interface is accessible via plaintext HTTP protocol, facilitating the attack. The HTTP request may contain the session cookie in the request, which may be captured for use in authenticating to the server.

Details CVE

Score CVSS v3.15.7
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Vecteur d'attaqueADJACENT_NETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurREQUIRED
Publie8/17/2022
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0

Produits affectes

softing:edgeaggregatorsofting:edgeconnectorsofting:opcsofting:opc_ua_c\+\+_software_development_kitsofting:secure_integration_serversofting:uagates

Faiblesses (CWE)

CWE-319

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.