- Description
- Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`. This allows Softing to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the `admin` password. There is no warning or prompt to ask the user to change the default password, and to change the password, many steps are required.
- Source
- ics-cert@hq.dhs.gov
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- ics-cert@hq.dhs.gov
- CWE-287
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:softing:edgeaggregator:3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C0E07A55-5FA0-402D-BB22-FA8D3D8C484D"
},
{
"criteria": "cpe:2.3:a:softing:edgeconnector:3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "62FE322E-A720-4E08-9058-3BAC295E720B"
},
{
"criteria": "cpe:2.3:a:softing:opc:5.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A9916828-8213-47D4-B294-8112B241F32C"
},
{
"criteria": "cpe:2.3:a:softing:opc_ua_c\\+\\+_software_development_kit:6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BA185EBD-8048-4B1C-A476-4AE61831ACF7"
},
{
"criteria": "cpe:2.3:a:softing:secure_integration_server:1.22:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0BF8EC24-9C94-4C55-A496-5DD524B981C4"
},
{
"criteria": "cpe:2.3:a:softing:uagates:1.74:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2DD68DEC-1E1C-456F-8FC2-F3EF9A72B012"
}
],
"operator": "OR"
}
]
}
]