Use After Free Vulnerability in Softing SmartLink Webserver
CVE-2024-14028

6.5MEDIUM

Key Information:

Vendor

Softing

Vendor
CVE Published:
27 March 2026

What is CVE-2024-14028?

A use after free vulnerability exists in Softing smartLink HW-DP and smartLink HW-PN webservers, potentially allowing malicious actors to execute HTTP denial-of-service attacks. This flaw can lead to increased downtime and service disruptions for users, impacting the availability of critical industrial applications. It is essential for users of affected versions to promptly apply security updates and review their network security posture to safeguard against exploitation.

Affected Version(s)

smartLink HW-DP 0 <= 1.31

smartLink HW-PN 0 < 1.02

smartLink HW-DP 1.32

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.