CVE-2022-2336
Softing Secure Integration Server Improper Authentication
Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`. This allows Softing to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the `admin` password. There is no warning or prompt to ask the user to change the default password, and to change the password, many steps are required.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Softing · edgeAggregatorSofting · edgeConnector 840DSofting · edgeConnector ModbusSofting · edgeConnector SiemensSofting · Secure Integration ServerQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →