Softing
- Total products in the ecosystem
- 15
- Total vulnerabilities (90 days)
- 2
en
Verify to analyze this security profile
As of 09/15/2026, Softing recorded 2 security vulnerabilities in the last 90 days across 2 products, including 0 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, Secure Integration Server had the most security vulnerabilities in the Softing ecosystem, with 1 vulnerabilities—approximately 50% of the provider's total vulnerabilities during this period.
| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2023-29377 | Exploitation statusNot confirmed | FixYes | Affected productSecure Integration Server | Published09/14/2026 | SeverityMedium |
CVE-2026-13148Memory leak in scan method | Exploitation statusNot known exploited | FixYes | Affected productsmartLink HW-PN | Published09/04/2026 | SeverityMedium |
CVE-2023-7339Data collection for dowloading leads into buffer overflow | Exploitation statusNot known exploited | FixYes | Affected productpnGate | Published03/27/2026 | SeverityMedium |
CVE-2024-14028Multiple implicit reads in parallel can result in a crash or denial of service | Exploitation statusNot known exploited | FixYes | Affected productsmartLink HW-DP | Published03/27/2026 | SeverityMedium |
CVE-2025-13406Scanning for higher HART revision device leads into NULL pointer dereference in live list | Exploitation statusNot known exploited | FixYes | Affected productsmartLink SW-HT | Published03/17/2026 | SeverityMedium |
CVE-2025-10461Global file reads caused by improper URL checks in webserver | Exploitation statusNot known exploited | FixYes | Affected productsmartLink SW-HT | Published03/16/2026 | SeverityMedium |
CVE-2025-10685HTTP POST with specific higher content length leads into heap corruption | Exploitation statusNot known exploited | FixYes | Affected productsmartLink SW-PN | Published03/16/2026 | SeverityHigh |
CVE-2025-7390Bypass the client certificate trust check of an opc.https server while only secure communication is allowed | Exploitation statusNot known exploited | FixYes | Affected productOPC UA C++ SDK | Published08/21/2025 | SeverityCritical |
CVE-2023-39482Softing Secure Integration Server Hardcoded Cryptographic Key Information Disclosure Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productSecure Integration Server | Published05/03/2024 | SeverityMedium |
CVE-2023-39481Softing Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productSecure Integration Server | Published05/03/2024 | SeverityMedium |
CVE-2023-39480Softing Secure Integration Server FileDirectory OPC UA Object Arbitrary File Creation Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productSecure Integration Server | Published05/03/2024 | SeverityMedium |
CVE-2023-39479Softing Secure Integration Server OPC UA Gateway Directory Creation Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productSecure Integration Server | Published05/03/2024 | SeverityMedium |
CVE-2023-39478Softing Secure Integration Server Exposure of Resource to Wrong Sphere Remote Code Execution Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productSecure Integration Server | Published05/03/2024 | SeverityMedium |
CVE-2023-38125Softing edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code Execution Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productedgeAggregator | Published05/03/2024 | SeverityHigh |
CVE-2023-27336Softing edgeConnector Siemens OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productedgeConnector Siemens | Published05/03/2024 | SeverityHigh |
CVE-2023-27335Softing edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productedgeAggregator | Published05/03/2024 | SeverityHigh |
CVE-2023-27334Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productedgeConnector Siemens | Published05/03/2024 | SeverityHigh |
CVE-2024-0860Cleartext Transmission of Sensitive Information in Softing edgeConnector and edgeAggregator | Exploitation statusNot known exploited | FixYes | Affected productedgeConnector | Published03/14/2024 | SeverityHigh |
CVE-2023-37571 | Exploitation statusNot known exploited | FixNot confirmed | Affected productNot confirmed | Published01/30/2024 | SeverityMedium |
CVE-2023-38126Softing edgeAggregator Restore Configuration Directory Traversal Remote Code Execution Vulnerability | Exploitation statusNot confirmed | FixNot confirmed | Affected productedgeAggregator | Published12/19/2023 | SeverityHigh |
CVE-2023-41151 | Exploitation statusNot known exploited | FixNot confirmed | Affected productNot confirmed | Published12/14/2023 | SeverityHigh |
CVE-2023-37572 | Exploitation statusNot known exploited | FixNot confirmed | Affected productNot confirmed | Published12/05/2023 | SeverityHigh |
CVE-2022-48193Weak ciphers vulnerability in Softing smartLink SW-HT | Exploitation statusNot known exploited | FixNot confirmed | Affected productNot confirmed | Published11/06/2023 | SeverityMedium |
CVE-2022-48192Cross-site scripting vulnerability in Softing smartLink SW-HT | Exploitation statusNot known exploited | FixNot confirmed | Affected productNot confirmed | Published11/06/2023 | SeverityHigh |
CVE-2022-44018 | Exploitation statusNot known exploited | FixNot confirmed | Affected productNot confirmed | Published01/25/2023 | SeverityHigh |
CVE-2022-45920 | Exploitation statusNot known exploited | FixNot confirmed | Affected productNot confirmed | Published01/25/2023 | SeverityHigh |
CVE-2022-39823 | Exploitation statusNot known exploited | FixNot confirmed | Affected productNot confirmed | Published10/20/2022 | SeverityHigh |
CVE-2022-37453 | Exploitation statusNot known exploited | FixNot confirmed | Affected productNot confirmed | Published10/20/2022 | SeverityHigh |
CVE-2022-2337Softing Secure Integration Server NULL Pointer Dereference | Exploitation statusNot known exploited | FixYes | Affected productSecure Integration Server | Published08/17/2022 | SeverityHigh |
CVE-2022-1069Softing Secure Integration Server Out-of-bounds Read | Exploitation statusNot known exploited | FixYes | Affected productSecure Integration Server | Published08/17/2022 | SeverityHigh |
CVE-2022-2338Softing Secure Integration Server Cleartext Transmission of Sensitive Information | Exploitation statusNot known exploited | FixYes | Affected productSecure Integration Server | Published08/17/2022 | SeverityMedium |
CVE-2022-2335Softing Secure Integration Server Integer Underflow | Exploitation statusNot known exploited | FixYes | Affected productSecure Integration Server | Published08/17/2022 | SeverityHigh |
CVE-2022-2334Softing Secure Integration Server Uncontrolled Search Path Element | Exploitation statusNot known exploited | FixYes | Affected productSecure Integration Server | Published08/17/2022 | SeverityHigh |
CVE-2022-1373Softing Secure Integration Server Relative Path Traversal | Exploitation statusNot known exploited | FixYes | Affected productSecure Integration Server | Published08/17/2022 | SeverityHigh |
CVE-2022-1748Softing Secure Integration Server NULL Pointer Dereference | Exploitation statusNot known exploited | FixYes | Affected productSecure Integration Server | Published08/17/2022 | SeverityHigh |
CVE-2022-2336Softing Secure Integration Server Improper Authentication | Exploitation statusNot known exploited | FixYes | Affected productSecure Integration Server | Published08/17/2022 | SeverityCritical |
CVE-2022-2547Softing Secure Integration Server NULL Pointer Dereference | Exploitation statusNot known exploited | FixYes | Affected productSecure Integration Server | Published08/17/2022 | SeverityHigh |
CVE-2021-32994Softing OPC-UA C++ SDK Improper Restriction of Operations within the Bounds of a Memory Buffer | Exploitation statusNot known exploited | FixYes | Affected productOPC UA C++ SDK (Software Development Kit) | Published04/04/2022 | SeverityHigh |
CVE-2021-42577 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published03/11/2022 | SeverityUnknown |
CVE-2021-42262 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published03/11/2022 | SeverityUnknown |
CVE-2021-40873 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published11/10/2021 | SeverityUnknown |
CVE-2021-40872 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published11/10/2021 | SeverityUnknown |
CVE-2021-40871 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published11/10/2021 | SeverityUnknown |
CVE-2021-29661 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published04/02/2021 | SeverityUnknown |
CVE-2021-29660 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published04/02/2021 | SeverityUnknown |
CVE-2020-14524Softing Industrial Automation OPC | Exploitation statusNot confirmed | FixYes | Affected productOPC | Published08/25/2020 | SeverityCritical |
CVE-2020-14522Softing Industrial Automation OPC | Exploitation statusNot confirmed | FixYes | Affected productOPC | Published08/25/2020 | SeverityHigh |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan