Softing Secure Integration Server Hardcoded Cryptographic Key Information Disclosure Vulnerability
CVE-2023-39482

6.5MEDIUM

Key Information:

Vendor

Softing

Vendor
CVE Published:
3 May 2024

What is CVE-2023-39482?

A vulnerability has been identified in the Softing Secure Integration Server that poses a risk of information disclosure. It stems from the hardcoding of cryptographic keys within the product's library, specifically libopcuaclient.so. Although the exploitation of this vulnerability necessitates the presence of authentication, it is noteworthy that the existing authentication mechanisms can be circumvented. Attackers exploiting this flaw can potentially obtain stored credentials, leading to significant security risks and further exploitation of the affected system. Organizations utilizing the Softing Secure Integration Server are recommended to assess their installations for this vulnerability to mitigate potential threats.

Affected Version(s)

Secure Integration Server 1.22.8686

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.