Show filters
45 Total Results
Displaying 31-40 of 45
Sort by:
Attacker Value
Unknown

CVE-2021-42577

Disclosure Date: March 11, 2022 (last updated February 23, 2025)
An issue was discovered in Softing OPC UA C++ SDK before 5.70. A malformed OPC/UA message abort packet makes the client crash with a NULL pointer dereference.
Attacker Value
Unknown

CVE-2021-42262

Disclosure Date: March 11, 2022 (last updated February 23, 2025)
An issue was discovered in Softing OPC UA C++ SDK before 5.70. An invalid XML element in the type dictionary makes the OPC/UA client crash due to an out-of-memory condition.
Attacker Value
Unknown

CVE-2021-40872

Disclosure Date: November 10, 2021 (last updated February 23, 2025)
An issue was discovered in Softing Industrial Automation uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) or login as an anonymous user (bypassing security checks) by sending crafted messages to a OPC/UA server. The server process may crash unexpectedly because of an invalid type cast, and must be restarted.
Attacker Value
Unknown

CVE-2021-40873

Disclosure Date: November 10, 2021 (last updated February 23, 2025)
An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a client or server. The server process may crash unexpectedly because of a double free, and must be restarted.
Attacker Value
Unknown

CVE-2021-40871

Disclosure Date: November 10, 2021 (last updated February 23, 2025)
An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a OPC/UA client. The client process may crash unexpectedly because of a wrong type cast, and must be restarted.
Attacker Value
Unknown

CVE-2021-29661

Disclosure Date: April 02, 2021 (last updated February 22, 2025)
Softing AG OPC Toolbox through 4.10.1.13035 allows /en/diag_values.html Stored XSS via the ITEMLISTVALUES##ITEMID parameter, resulting in JavaScript payload injection into the trace file. This payload will then be triggered every time an authenticated user browses the page containing it.
Attacker Value
Unknown

CVE-2021-29660

Disclosure Date: April 02, 2021 (last updated February 22, 2025)
A Cross-Site Request Forgery (CSRF) vulnerability in en/cfg_setpwd.html in Softing AG OPC Toolbox through 4.10.1.13035 allows attackers to reset the administrative password by inducing the Administrator user to browse a URL controlled by an attacker.
Attacker Value
Unknown

CVE-2020-14522

Disclosure Date: August 25, 2020 (last updated February 22, 2025)
Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to uncontrolled resource consumption, which may allow an attacker to cause a denial-of-service condition.
Attacker Value
Unknown

CVE-2020-14524

Disclosure Date: August 25, 2020 (last updated February 22, 2025)
Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.
Attacker Value
Unknown

CVE-2019-11528

Disclosure Date: October 10, 2019 (last updated November 27, 2024)
An issue was discovered in Softing uaGate SI 1.60.01. A system default path for executables is user writable.