← back
CVE-2022-2334highCWE-427

Softing Secure Integration Server Uncontrolled Search Path Element

36Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 7.2epss 9.9%
from disclosure to weapon0 days
Published on NVDAug 17
metasploitJul 27
exploitation probability
9.9%top 5% of all CVEs
observed exploitation
nono source reports it
The application searches for a library dll that is not found. If an attacker can place a dll with this name, then the attacker can leverage it to execute arbitrary code on the targeted Softing Secure Integration Server V1.22.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H