← Vulnerability feed

Vulnerability record · CVE-2022-1748 · published 17 August 2022

CVE-2022-1748: Softing edgeaggregator null pointer dereference vulnerability

Softing · Edgeaggregator

Softing OPC UA C++ Server SDK, Secure Integration Server, edgeConnector, edgeAggregator, OPC Suite, and uaGate are affected by a NULL pointer dereference vulnerability.

7.5 CVSS 3.1 High EPSS 0.98% · top 39.4% CWE-476 · NULL pointer dereference
7.5CVSS 3.1 base score
0.98%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Softing OPC UA C++ Server SDK, Secure Integration Server, edgeConnector, edgeAggregator, OPC Suite, and uaGate are affected by a NULL pointer dereference vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://industrial.softing.com/fileadmin/psirt/downloads/syt-2022-7.html MitigationVendor Advisory
https://www.cisa.gov/uscert/ics/advisories/icsa-22-228-04 MitigationThird Party AdvisoryUS Government Resource
https://industrial.softing.com/fileadmin/psirt/downloads/syt-2022-7.html MitigationVendor Advisory
https://www.cisa.gov/uscert/ics/advisories/icsa-22-228-04 MitigationThird Party AdvisoryUS Government Resource

Track CVE-2022-1748 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-2336Softing edgeaggregator improper authentication vulnerabilitySofting Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and passwor…EPSS 1.00%9.8CVE-2020-14524Softing opc heap-based buffer overflow vulnerabilitySofting Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to a heap-based buffer ove…EPSS 2.5%9.6CVE-2023-27335Softing edgeaggregator cross-site scripting vulnerabilitySofting edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitra…EPSS 1.4%8.8CVE-2023-39478Softing secure integration server exposure of resource to wrong sphere vulnerabilitySofting Secure Integration Server Exposure of Resource to Wrong Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attacker…EPSS 1.6%8.8CVE-2023-39479Softing secure integration server vulnerabilitySofting Secure Integration Server OPC UA Gateway Directory Creation Vulnerability. This vulnerability allows remote attackers to create directories o…EPSS 1.6%8.8CVE-2023-39481Softing secure integration server interpretation conflict vulnerabilitySofting Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute …EPSS 1.6%8.8CVE-2023-38125Softing edgeaggregator vulnerabilitySofting edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code Execution Vulnerability. This vulnerability allows remote at…EPSS 1.3%7.5CVE-2023-27334Softing edgeaggregator uncontrolled resource consumption vulnerabilitySofting edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to cre…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2022-1748), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.