Softing develops industrial integration and OPC (OLE for Process Control) middleware, including secure data-exchange servers, edge aggregators, and protocol-translation software that bridge operational-technology environments with enterprise networks. Although the vendor's product portfolio is focused, its exposure is amplified by the critical role these components play in manufacturing, utilities, and industrial-control architectures where patching cycles are long and connectivity demands are rising. Vulnerabilities recur across the OPC and edge-connector product lines through weakness classes including NULL-pointer dereferences, cross-site scripting in web-facing management interfaces, uncontrolled resource consumption, type-confusion flaws, and cleartext transmission of sensitive data—patterns characteristic of middleware that must translate between legacy industrial protocols and modern networked systems. The recurring weakness classes reflect both parser complexity and the historical assumption in OT environments that network isolation would serve as a primary defense. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Softing over time
Of all the CVEs published by Softing as a CNA, 0.0% affect products that Softing develops as a vendor.
Of all the CVEs published that affect products developed by Softing, 0.0% are self-published by Softing as a CNA.
Signals from CVEs in this vendor scope (44 CVEs).
44 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-38126HIGH Softing edgeAggregator Restore Configuration Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affect | Dec 19, 2023 | 7.2 | 57 | NO | NO |
CVE-2022-2334HIGH The application searches for a library dll that is not found. If an attacker can place a dll with this name, then the attacker can leverage it to execute arbitrary code on the targ | Aug 17, 2022 | 7.2 | 39 | NO | YES |
CVE-2022-1373HIGH The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. An attacker can craft | Aug 17, 2022 | 7.2 | 34 | NO | YES |
CVE-2022-2336CRITICAL Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`. This allows Softi | Aug 17, 2022 | 9.8 | 32 | NO | NO |
CVE-2020-14524CRITICAL Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to a heap-based buffer overflow, which may allow an attac | Aug 25, 2020 | 9.8 | 30 | NO | NO |
CVE-2019-11526CRITICAL An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable to file path injection. This enables the Attacker to write fi | Oct 10, 2019 | 9.8 | 29 | NO | NO |
CVE-2021-29660HIGH A Cross-Site Request Forgery (CSRF) vulnerability in en/cfg_setpwd.html in Softing AG OPC Toolbox through 4.10.1.13035 allows attackers to reset the administrative password by indu | Apr 2, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-11527HIGH An issue was discovered in Softing uaGate SI 1.60.01. A CGI script is vulnerable to command injection with a maliciously crafted url parameter. | Oct 10, 2019 | 8.8 | 27 | NO | NO |
CVE-2023-38125HIGH Softing edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary co | May 3, 2024 | 8.8 | 26 | NO | NO |
CVE-2019-15051HIGH An issue was discovered in Softing uaGate (SI, MB, 840D) firmware through 1.71.00.1225. A CGI script is vulnerable to command injection via a maliciously crafted form parameter. | Oct 10, 2019 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (44 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Softing.
Media articles that mention a CVE ID that affects a product developed by Softing — matched by CVE ID, not by vendor name.