CVE-2022-37453: Buffer Overflow
An issue was discovered in Softing OPC UA C++ SDK before 6.10. A buffer overflow or an excess allocation happens due to unchecked array and matrix bounds in structure data types.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-37453?
CVE-2022-37453 is a vulnerability discovered in Softing OPC UA C++ SDK before version 6.10, which allows for a buffer overflow or an excess allocation due to unchecked array and matrix bounds in structure data types.
What software is affected by CVE-2022-37453?
The following Softing software versions are affected: Softing Edgeaggregator up to version 3.50, Softing Edgeconnector up to version 3.50, Softing OPC up to version 5.22, Softing Opc Ua C++ Software Development Kit up to version 6.00, Softing Secure Integration Server up to version 1.22, and Softing Uagates up to version 1.74.
How severe is CVE-2022-37453?
CVE-2022-37453 has a severity rating of 7.5 (High).
How can I fix CVE-2022-37453?
To fix CVE-2022-37453, users should upgrade to Softing OPC UA C++ SDK version 6.10 or later.
Are there any references for CVE-2022-37453?
Yes, you can find more information about CVE-2022-37453 at the official Softing PSIRT Advisory at https://industrial.softing.com/fileadmin/psirt/downloads/syt-2022-9.html and the Softing website at https://softing.com.