← Vulnerability feed

Vulnerability record · CVE-2022-2336 · published 17 August 2022

CVE-2022-2336: Softing edgeaggregator improper authentication vulnerability

Softing · Edgeaggregator

Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`. This allows Softing to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the `admin` password. There is no warning or prompt to ask the user to change the default password, and to change the password, many steps are required.

9.8 CVSS 3.1 Critical EPSS 1.00% · top 38.8% CWE-287 · Improper authentication
9.8CVSS 3.1 base score
1.00%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`. This allows Softing to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the `admin` password. There is no warning or prompt to ask the user to change the default password, and to change the password, many steps are required.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-2336 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-14524Softing opc heap-based buffer overflow vulnerabilitySofting Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to a heap-based buffer ove…EPSS 2.5%9.6CVE-2023-27335Softing edgeaggregator cross-site scripting vulnerabilitySofting edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitra…EPSS 1.4%8.8CVE-2023-39478Softing secure integration server exposure of resource to wrong sphere vulnerabilitySofting Secure Integration Server Exposure of Resource to Wrong Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attacker…EPSS 1.6%8.8CVE-2023-39479Softing secure integration server vulnerabilitySofting Secure Integration Server OPC UA Gateway Directory Creation Vulnerability. This vulnerability allows remote attackers to create directories o…EPSS 1.6%8.8CVE-2023-39481Softing secure integration server interpretation conflict vulnerabilitySofting Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute …EPSS 1.6%8.8CVE-2023-38125Softing edgeaggregator vulnerabilitySofting edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code Execution Vulnerability. This vulnerability allows remote at…EPSS 1.3%7.5CVE-2023-27334Softing edgeaggregator uncontrolled resource consumption vulnerabilitySofting edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to cre…EPSS 1.4%7.5CVE-2023-27336Softing edgeaggregator null pointer dereference vulnerabilitySofting edgeConnector Siemens OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability. This vulnerability allows remote attackers to c…EPSS 0.81%

Source: NIST National Vulnerability Database (record CVE-2022-2336), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.