CVE-2022-2336: Softing Secure Integration Server Improper Authentication
Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as admin and password as admin. This allows Softing to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the admin password. There is no warning or prompt to ask the user to change the default password, and to change the password, many steps are required.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-2336?
CVE-2022-2336 is a vulnerability found in Softing Secure Integration Server, edgeConnector, and edgeAggregator software, where the default administrator credentials are set as username 'admin' and password 'admin'.
What is the severity level of CVE-2022-2336?
The severity level of CVE-2022-2336 is critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2022-2336?
Softing Edgeaggregator version 3.1, Softing Edgeconnector version 3.1, Softing OPC version 5.2, Softing Opc Ua C++ Software Development Kit version 6, Softing Secure Integration Server version 1.22, and Softing Uagates version 1.74 are affected by CVE-2022-2336.
How can I fix CVE-2022-2336?
To fix CVE-2022-2336, it is recommended to change the default administrator credentials (username: 'admin' and password: 'admin') to strong, unique credentials.
Where can I find more information about CVE-2022-2336?
More information about CVE-2022-2336 can be found at the following references: [Reference 1](https://industrial.softing.com/fileadmin/psirt/downloads/syt-2022-6.html), [Reference 2](https://www.cisa.gov/uscert/ics/advisories/icsa-22-228-04).