Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Softing

First CVE: Aug 31, 2015Active for: 11 yearsTotal CVEs: 44
51.1
VTI Score
TOP TARGET

Softing develops industrial integration and OPC (OLE for Process Control) middleware, including secure data-exchange servers, edge aggregators, and protocol-translation software that bridge operational-technology environments with enterprise networks. Although the vendor's product portfolio is focused, its exposure is amplified by the critical role these components play in manufacturing, utilities, and industrial-control architectures where patching cycles are long and connectivity demands are rising. Vulnerabilities recur across the OPC and edge-connector product lines through weakness classes including NULL-pointer dereferences, cross-site scripting in web-facing management interfaces, uncontrolled resource consumption, type-confusion flaws, and cleartext transmission of sensitive data—patterns characteristic of middleware that must translate between legacy industrial protocols and modern networked systems. The recurring weakness classes reflect both parser complexity and the historical assumption in OT environments that network isolation would serve as a primary defense. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
44
Total CVEs
More Total CVEs than 98% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Softing over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 31, 2015
10 years ago
Most Recent CVE
May 3, 2024
812 days ago

Self-Reporting Analysis

Of all the CVEs published by Softing as a CNA, 0.0% affect products that Softing develops as a vendor.

100.0%
Self-reported: 0 (0.0%)
Third-party: 8 (100.0%)

Of all the CVEs published that affect products developed by Softing, 0.0% are self-published by Softing as a CNA.

100.0%
Self-published: 0 (0.0%)
Other CNAs: 44 (100.0%)

Products(20 total)

Top CVEs

Signals from CVEs in this vendor scope (44 CVEs).

44 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-38126HIGH
Softing edgeAggregator Restore Configuration Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affect
Dec 19, 20237.257NONO
CVE-2022-2334HIGH
The application searches for a library dll that is not found. If an attacker can place a dll with this name, then the attacker can leverage it to execute arbitrary code on the targ
Aug 17, 20227.239NOYES
CVE-2022-1373HIGH
The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. An attacker can craft
Aug 17, 20227.234NOYES
CVE-2022-2336CRITICAL
Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`. This allows Softi
Aug 17, 20229.832NONO
CVE-2020-14524CRITICAL
Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to a heap-based buffer overflow, which may allow an attac
Aug 25, 20209.830NONO
CVE-2019-11526CRITICAL
An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable to file path injection. This enables the Attacker to write fi
Oct 10, 20199.829NONO
CVE-2021-29660HIGH
A Cross-Site Request Forgery (CSRF) vulnerability in en/cfg_setpwd.html in Softing AG OPC Toolbox through 4.10.1.13035 allows attackers to reset the administrative password by indu
Apr 2, 20218.827NONO
CVE-2019-11527HIGH
An issue was discovered in Softing uaGate SI 1.60.01. A CGI script is vulnerable to command injection with a maliciously crafted url parameter.
Oct 10, 20198.827NONO
CVE-2023-38125HIGH
Softing edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary co
May 3, 20248.826NONO
CVE-2019-15051HIGH
An issue was discovered in Softing uaGate (SI, MB, 840D) firmware through 1.71.00.1225. A CGI script is vulnerable to command injection via a maliciously crafted form parameter.
Oct 10, 20198.826NONO
View all 44 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products44 CVEs
18%
73%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network42 (95.5%)
Unknown1 (2.3%)
Physical0 (0.0%)
Adjacent Network1 (2.3%)
Attack Complexity
Low42 (95.5%)
High1 (2.3%)
Unknown1 (2.3%)
User Interaction
None38 (86.4%)
Unknown1 (2.3%)
Required5 (11.4%)
Privileges Required
Low10 (22.7%)
High3 (6.8%)
None30 (68.2%)
Unknown1 (2.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (44 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
4.5% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Softing.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Softing — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Softing's Products

View all 3 CNAs →

Top CWEs