SecAlerts
s

softing

Security Risk Profile

46
/100
medium

Security Risk Score

Comprehensive risk assessment based on 75 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from August 31, 2015 to present

75
Total CVEs
47
Critical+High
0
Exploited
37
Unpatched

Threat Assessment

Avg CVSS
7.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
37
Critical/High
Risk Level
46/100
medium
🆕 3Fresh (<7d)📈 3 in Last 30 Days

Severity Distribution

Critical
6
High
41
Medium
20
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
0

Age Distribution

Common Weaknesses (CWE)

1
Null Pointer Dereference
6
2
XSS
5
3
Buffer Overflow
4
4
Use After Free
2
5
Path Traversal
2

Most Affected Products

1. Softing Secure Integration Server41
2. Softing edgeAggregator37
3. Softing edgeConnector27
4. Softing OPC17
5. Softing Opc Ua C\+\+ Software Development Kit16

Recent Vulnerabilities

See more →
CVE-2026-13148
CVSS 6.3medium

Memory leak in scan method

Sep 4, 2026🔧 No Patch
CVE-2024-14028
CVSS 6.5medium

Multiple implicit reads in parallel can result in a crash or denial of service

Mar 27, 2026
CVE-2023-39482
CVSS 6.5medium

(0Day) Softing Secure Integration Server Hardcoded Cryptographic Key Information Disclosure Vulnerability

May 3, 2024🔧 No Patch
CVE-2023-39480
CVSS 6.5medium

(0Day) (Pwn2Own) Softing Secure Integration Server FileDirectory OPC UA Object Arbitrary File Creation Vulnerability

May 3, 2024🔧 No Patch
CVE-2023-39481
CVSS 8.8high

(0Day) (Pwn2Own) Softing Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerability

May 3, 2024🔧 No Patch
CVE-2023-39479
CVSS 8.8high

(0Day) (Pwn2Own) Softing Secure Integration Server OPC UA Gateway Directory Creation Vulnerability

May 3, 2024🔧 No Patch
CVE-2023-39478
CVSS 8.8high

(0Day) (Pwn2Own) Softing Secure Integration Server Exposure of Resource to Wrong Sphere Remote Code Execution Vulnerability

May 3, 2024🔧 No Patch
CVE-2023-38125
CVSS 8.8high

(0Day) (Pwn2Own) Softing edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code Execution Vulnerability

May 3, 2024🔧 No Patch
CVE-2023-27336
CVSS 7.5high

(0Day) (Pwn2Own) Softing edgeConnector Siemens OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability

May 3, 2024🔧 No Patch
CVE-2023-27335
CVSS 9.6critical

(0Day) (Pwn2Own) Softing edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability

May 3, 2024🔧 No Patch

Monitor softing in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.