CVE-2023-38126 – Softing edgeAggregator Restore Configuration Directory Traversal Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2023-38126
Softing edgeAggregator Restore Configuration Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of backup zip files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this to execute code in the context of root. • https://www.zerodayinitiative.com/advisories/ZDI-23-1058 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2022-45920
https://notcve.org/view.php?id=CVE-2022-45920
In Softing uaToolkit Embedded before 1.41, a malformed CreateMonitoredItems request may cause a memory leak. En Softing uaToolkit Embedded anterior a 1.41, una solicitud CreateMonitoredItems con formato incorrecto puede causar una pérdida de memoria. • https://industrial.softing.com/fileadmin/psirt/downloads/syt-2022-10.html • CWE-401: Missing Release of Memory after Effective Lifetime •
CVE-2022-44018
https://notcve.org/view.php?id=CVE-2022-44018
In Softing uaToolkit Embedded before 1.40.1, a malformed PubSub discovery announcement message can cause a NULL pointer dereference or out-of-bounds memory access in the subscriber application. En Softing uaToolkit Embedded anterior a 1.40.1, un mensaje de anuncio de descubrimiento de PubSub con formato incorrecto puede provocar una desreferencia del puntero NULL o un acceso a la memoria fuera de los límites en la aplicación del suscriptor. • https://industrial.softing.com/fileadmin/psirt/downloads/syt-2022-10.html • CWE-476: NULL Pointer Dereference •
CVE-2022-39823
https://notcve.org/view.php?id=CVE-2022-39823
An issue was discovered in Softing OPC UA C++ SDK 5.66 through 6.x before 6.10. An OPC/UA browse request exceeding the server limit on continuation points may cause a use-after-free error Se ha detectado un problema en Softing OPC UA C++ SDK versiones 5.66 hasta 6.x anteriores a 6.10. Una petición de exploración OPC/UA que exceda el límite del servidor en puntos de continuación puede causar un error de uso de memoria previamente liberada • https://industrial.softing.com/fileadmin/psirt/downloads/syt-2022-8.html https://www.softing.com • CWE-416: Use After Free •
CVE-2022-37453
https://notcve.org/view.php?id=CVE-2022-37453
An issue was discovered in Softing OPC UA C++ SDK before 6.10. A buffer overflow or an excess allocation happens due to unchecked array and matrix bounds in structure data types. Se ha detectado un problema en Softing OPC UA C++ SDK versiones anteriores a 6.10. Es producido un desbordamiento del búfer o un exceso de asignación debido a los límites de matrices y arrays no comprobados en los tipos de datos de estructuras • https://industrial.softing.com/fileadmin/psirt/downloads/syt-2022-9.html https://softing.com • CWE-787: Out-of-bounds Write •