CVE-2022-2334: Softing Secure Integration Server Uncontrolled Search Path Element
The application searches for a library dll that is not found. If an attacker can place a dll with this name, then the attacker can leverage it to execute arbitrary code on the targeted Softing Secure Integration Server V1.22.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-2334?
CVE-2022-2334 is a vulnerability that allows an attacker to execute arbitrary code on the targeted Softing Secure Integration Server V1.22.
How does CVE-2022-2334 work?
CVE-2022-2334 occurs when the application searches for a library DLL that is not found, and if an attacker can place a DLL with the same name, they can leverage it to execute arbitrary code.
What software is affected by CVE-2022-2334?
Softing Edgeaggregator, Softing Edgeconnector, Softing OPC, Softing Opc Ua C++ Software Development Kit, Softing Secure Integration Server, and Softing Uagates are affected by CVE-2022-2334.
What is the severity of CVE-2022-2334?
The severity of CVE-2022-2334 is high, with a CVSS severity score of 7.2.
How do I fix CVE-2022-2334?
To fix CVE-2022-2334, it is recommended to apply the software patches provided by Softing and follow the recommendations outlined in the security advisory.