← Vulnerability feed

Vulnerability record · CVE-2022-2334 · published 17 August 2022

CVE-2022-2334: Softing edgeaggregator uncontrolled search path element vulnerability

Softing · Edgeaggregator

The application searches for a library dll that is not found. If an attacker can place a dll with this name, then the attacker can leverage it to execute arbitrary code on the targeted Softing Secure Integration Server V1.22.

7.2 CVSS 3.1 High EPSS 12% · top 4.0% CWE-427 · Uncontrolled search path element
7.2CVSS 3.1 base score
12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The application searches for a library dll that is not found. If an attacker can place a dll with this name, then the attacker can leverage it to execute arbitrary code on the targeted Softing Secure Integration Server V1.22.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://industrial.softing.com/fileadmin/psirt/downloads/syt-2022-5.html MitigationVendor Advisory
https://www.cisa.gov/uscert/ics/advisories/icsa-22-228-04 MitigationThird Party AdvisoryUS Government Resource
https://industrial.softing.com/fileadmin/psirt/downloads/syt-2022-5.html MitigationVendor Advisory
https://www.cisa.gov/uscert/ics/advisories/icsa-22-228-04 MitigationThird Party AdvisoryUS Government Resource

Track CVE-2022-2334 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-2336Softing edgeaggregator improper authentication vulnerabilitySofting Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and passwor…EPSS 1.00%9.8CVE-2020-14524Softing opc heap-based buffer overflow vulnerabilitySofting Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to a heap-based buffer ove…EPSS 2.5%9.6CVE-2023-27335Softing edgeaggregator cross-site scripting vulnerabilitySofting edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitra…EPSS 1.4%8.8CVE-2023-39478Softing secure integration server exposure of resource to wrong sphere vulnerabilitySofting Secure Integration Server Exposure of Resource to Wrong Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attacker…EPSS 1.6%8.8CVE-2023-39479Softing secure integration server vulnerabilitySofting Secure Integration Server OPC UA Gateway Directory Creation Vulnerability. This vulnerability allows remote attackers to create directories o…EPSS 1.6%8.8CVE-2023-39481Softing secure integration server interpretation conflict vulnerabilitySofting Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute …EPSS 1.6%8.8CVE-2023-38125Softing edgeaggregator vulnerabilitySofting edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code Execution Vulnerability. This vulnerability allows remote at…EPSS 1.3%7.5CVE-2023-27334Softing edgeaggregator uncontrolled resource consumption vulnerabilitySofting edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to cre…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2022-2334), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.