CVE-2022-2336
CVE-2022-2336 is a critical-severity vulnerability in Softing Edgeaggregator with a CVSS 3.x base score of 9.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-287.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- EPSS exploit prediction: 1% (61st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-287
- Affected product: Softing Edgeaggregator
- Published:
- Last modified:
Description
Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`. This allows Softing to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the `admin` password. There is no warning or prompt to ask the user to change the default password, and to change the password, many steps are required.
Frequently asked questions
- What is CVE-2022-2336?
- Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`. This allows Softing to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the `admin` password. There is no warning or prompt to ask the user to change the default password, and to change the password, many steps are required.
- How severe is CVE-2022-2336?
- CVE-2022-2336 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2022-2336 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (61st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2022-2336?
- CVE-2022-2336 primarily affects Softing Edgeaggregator. In total, 6 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2022-2336?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2022-2336 published?
- CVE-2022-2336 was published on 2022-08-17 and last updated on 2026-06-17.
References
- https://industrial.softing.com/fileadmin/psirt/downloads/syt-2022-6.html
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-228-04
Affected products (6)
- cpe:2.3:a:softing:edgeaggregator:3.1:*:*:*:*:*:*:*
- cpe:2.3:a:softing:edgeconnector:3.1:*:*:*:*:*:*:*
- cpe:2.3:a:softing:opc:5.2:*:*:*:*:*:*:*
- cpe:2.3:a:softing:opc_ua_c\+\+_software_development_kit:6:*:*:*:*:*:*:*
- cpe:2.3:a:softing:secure_integration_server:1.22:*:*:*:*:*:*:*
- cpe:2.3:a:softing:uagates:1.74:*:*:*:*:*:*:*
More vulnerabilities in Softing Edgeaggregator
- CVE-2023-27335 — Critical (CVSS 9.6): Softing edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows…
- CVE-2023-38125 — High (CVSS 8.8): Softing edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code Execution Vulnerability. This…
- CVE-2024-0860 — High (CVSS 8.0): The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow…
- CVE-2023-27336 — High (CVSS 7.5): Softing edgeConnector Siemens OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability. This…
- CVE-2023-27334 — High (CVSS 7.5): Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability…
- CVE-2022-37453 — High (CVSS 7.5): An issue was discovered in Softing OPC UA C++ SDK before 6.10. A buffer overflow or an excess allocation happens due to…
All CVEs affecting Softing Edgeaggregator →
Other CWE-287 (Improper Authentication) vulnerabilities
- CVE-2026-101077 — Critical (CVSS 10.0): A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp…
- CVE-2026-100886 — Critical (CVSS 10.0): A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected…
- CVE-2026-77244 — Critical (CVSS 10.0): MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0,…
- CVE-2026-94493 — Critical (CVSS 10.0): A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of…
- CVE-2026-83099 — Critical (CVSS 10.0): Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).…
- CVE-2026-83059 — Critical (CVSS 10.0): Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).…
Browse all CWE-287 (Improper Authentication) vulnerabilities →