Softing Secure Integration Server Hardcoded Cryptographic Key Information Disclosure Vulnerability
CVE-2023-39482
What is CVE-2023-39482?
A vulnerability has been identified in the Softing Secure Integration Server that poses a risk of information disclosure. It stems from the hardcoding of cryptographic keys within the product's library, specifically libopcuaclient.so. Although the exploitation of this vulnerability necessitates the presence of authentication, it is noteworthy that the existing authentication mechanisms can be circumvented. Attackers exploiting this flaw can potentially obtain stored credentials, leading to significant security risks and further exploitation of the affected system. Organizations utilizing the Softing Secure Integration Server are recommended to assess their installations for this vulnerability to mitigate potential threats.
Affected Version(s)
Secure Integration Server 1.22.8686
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
