CVE-2022-2338: Softing Secure Integration Server Cleartext Transmission of Sensitive Information
Softing Secure Integration Server V1.22 is vulnerable to authentication bypass via a machine-in-the-middle attack. The default the administration interface is accessible via plaintext HTTP protocol, facilitating the attack. The HTTP request may contain the session cookie in the request, which may be captured for use in authenticating to the server.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for Softing Secure Integration Server?
The vulnerability ID for Softing Secure Integration Server is CVE-2022-2338.
What is the severity of CVE-2022-2338?
The severity of CVE-2022-2338 is medium with a severity value of 5.3.
How does CVE-2022-2338 affect Softing Secure Integration Server?
CVE-2022-2338 affects Softing Secure Integration Server by allowing authentication bypass through a machine-in-the-middle attack.
How can I fix CVE-2022-2338 in Softing Secure Integration Server?
To fix CVE-2022-2338 in Softing Secure Integration Server, ensure that the administration interface is only accessible via encrypted protocols like HTTPS.
Where can I find more information about CVE-2022-2338?
You can find more information about CVE-2022-2338 on the Softing PSIRT website and the CISA ICS-CERT website.