Vulnerabilities > Softing

DATE CVE VULNERABILITY TITLE RISK
2020-08-25 CVE-2020-14522 Resource Exhaustion vulnerability in Softing OPC
Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to uncontrolled resource consumption, which may allow an attacker to cause a denial-of-service condition.
network
low complexity
softing CWE-400
5.0
2019-10-10 CVE-2019-15051 Command Injection vulnerability in Softing products
An issue was discovered in Softing uaGate (SI, MB, 840D) firmware through 1.71.00.1225.
network
low complexity
softing CWE-77
critical
9.0
2019-10-10 CVE-2019-11528 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Softing Uagate SI Firmware 1.60.01
An issue was discovered in Softing uaGate SI 1.60.01.
network
low complexity
softing CWE-119
5.0
2019-10-10 CVE-2019-11527 OS Command Injection vulnerability in Softing Uagate SI Firmware 1.60.01
An issue was discovered in Softing uaGate SI 1.60.01.
network
low complexity
softing CWE-78
critical
9.0
2019-10-10 CVE-2019-11526 Code Injection vulnerability in Softing Uagate SI Firmware 1.60.01
An issue was discovered in Softing uaGate SI 1.60.01.
network
low complexity
softing CWE-94
critical
10.0
2015-08-31 CVE-2014-6616 Cross-site Scripting vulnerability in Softing Fg-X00 Profibus Firmware 2.02.0.00
Cross-site scripting (XSS) vulnerability in Softing FG-100 PROFIBUS Single Channel (FG-100-PB) with firmware FG-x00-PB_V2.02.0.00 allows remote attackers to inject arbitrary web script or HTML via the DEVICE_NAME parameter to cgi-bin/CFGhttp/.
network
softing CWE-79
4.3