Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Softing — Vulnerabilities & Security Advisories 29

Browse all 29 CVE security advisories affecting Softing. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Softing AG specializes in industrial communication solutions, providing hardware and software for connecting automation systems, particularly in automotive and manufacturing sectors. Its product portfolio includes gateways, switches, and software for protocols like CANopen and PROFINET, facilitating data exchange between field devices and higher-level control systems. Historically, the company’s software components have exhibited vulnerabilities such as remote code execution, buffer overflows, and improper access control, often stemming from complex network stack implementations. Notable incidents include critical flaws allowing unauthorized command execution or denial of service within industrial networks. These weaknesses highlight risks in legacy protocols and embedded systems where security updates may be delayed. The accumulation of twenty-seven CVEs underscores the challenges in maintaining secure codebases for specialized industrial IoT infrastructure, emphasizing the need for rigorous patch management and secure configuration practices in critical operational technology environments.

CVE ID Title CVSS Severity Published
CVE-2023-29377 Softing OPC UA C++ SDK 路径遍历漏洞 — Secure Integration Server CWE-23 6.6 Medium 2026-09-14
CVE-2026-13148 Memory leak in scan method — smartLink HW-PN CWE-401 6.3 Medium 2026-09-04
CVE-2023-7339 Data collection for dowloading leads into buffer overflow — pnGate CWE-121 6.5 Medium 2026-03-27
CVE-2024-14028 Multiple implicit reads in parallel can result in a crash or denial of service — smartLink HW-DP CWE-416 6.5 Medium 2026-03-27
CVE-2025-13406 Scanning for higher HART revision device leads into NULL pointer dereference in live list — smartLink SW-HT CWE-476 7.5AI High AI 2026-03-17
CVE-2025-10461 Global file reads caused by improper URL checks in webserver — smartLink SW-HT CWE-20 7.5AI High AI 2026-03-16
CVE-2025-10685 HTTP POST with specific higher content length leads into heap corruption — smartLink SW-PN CWE-122 9.8AI Critical AI 2026-03-16
CVE-2025-7390 Bypass the client certificate trust check of an opc.https server while only secure communication is allowed — OPC UA C++ SDK CWE-295 9.1 Critical 2025-08-21
CVE-2023-39482 Softing Secure Integration Server Hardcoded Cryptographic Key Information Disclosure Vulnerability — Secure Integration Server CWE-321 6.5 - 2024-05-03
CVE-2023-39481 Softing Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerability — Secure Integration Server CWE-436 8.8 - 2024-05-03
CVE-2023-39480 Softing Secure Integration Server FileDirectory OPC UA Object Arbitrary File Creation Vulnerability — Secure Integration Server CWE-552 8.1 - 2024-05-03
CVE-2023-39479 Softing Secure Integration Server OPC UA Gateway Directory Creation Vulnerability — Secure Integration Server CWE-552 6.5 - 2024-05-03
CVE-2023-39478 Softing Secure Integration Server Exposure of Resource to Wrong Sphere Remote Code Execution Vulnerability — Secure Integration Server CWE-668 8.8 - 2024-05-03
CVE-2023-38125 Softing edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code Execution Vulnerability — edgeAggregator CWE-942 8.8 - 2024-05-03
CVE-2023-27335 Softing edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability — edgeAggregator CWE-79 8.3 - 2024-05-03
CVE-2023-27336 Softing edgeConnector Siemens OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability — edgeConnector Siemens CWE-476 7.5 - 2024-05-03
CVE-2023-27334 Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability — edgeConnector Siemens CWE-400 7.5 - 2024-05-03
CVE-2024-0860 Cleartext Transmission of Sensitive Information in Softing edgeConnector and edgeAggregator — edgeConnector CWE-319 8.0 High 2024-03-14
CVE-2023-38126 Softing edgeAggregator Restore Configuration Directory Traversal Remote Code Execution Vulnerability — edgeAggregator CWE-22 8.8 - 2023-12-19
CVE-2022-2337 Softing Secure Integration Server NULL Pointer Dereference — Secure Integration Server CWE-476 7.5 High 2022-08-17
CVE-2022-1069 Softing Secure Integration Server Out-of-bounds Read — Secure Integration Server CWE-125 7.5 High 2022-08-17
CVE-2022-2338 Softing Secure Integration Server Cleartext Transmission of Sensitive Information — Secure Integration Server CWE-319 5.7 Medium 2022-08-17
CVE-2022-2335 Softing Secure Integration Server Integer Underflow — Secure Integration Server CWE-191 7.5 High 2022-08-17
CVE-2022-2334 Softing Secure Integration Server Uncontrolled Search Path Element — Secure Integration Server CWE-427 7.2 High 2022-08-17
CVE-2022-1373 Softing Secure Integration Server Relative Path Traversal — Secure Integration Server CWE-23 7.2 High 2022-08-17
CVE-2022-1748 Softing Secure Integration Server NULL Pointer Dereference — Secure Integration Server CWE-476 7.5 High 2022-08-17
CVE-2022-2336 Softing Secure Integration Server Improper Authentication — Secure Integration Server CWE-287 9.8 Critical 2022-08-17
CVE-2022-2547 Softing Secure Integration Server NULL Pointer Dereference — Secure Integration Server CWE-476 7.5 High 2022-08-17
CVE-2021-32994 Softing OPC-UA C++ SDK Improper Restriction of Operations within the Bounds of a Memory Buffer — OPC UA C++ SDK (Software Development Kit) CWE-119 7.5 High 2022-04-04

This page lists every published CVE security advisory associated with Softing. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.