Description
Softing edgeConnector Siemens OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Siemens. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the handling of OPC client certificates. The issue results from dereferencing a NULL pointer. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-20508.
Published: 2024-05-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-31112 Softing edgeConnector Siemens OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Siemens. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of OPC client certificates. The issue results from dereferencing a NULL pointer. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-20508.
History

Wed, 25 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:softing:edgeconnector:-:*:*:*:*:*:*:*
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 13 Aug 2025 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Softing
Softing edgeaggregator
Softing edgeconnector
Softing secure Integration Server
CPEs cpe:2.3:a:softing:edgeaggregator:*:*:*:*:*:*:*:*
cpe:2.3:a:softing:edgeconnector:*:*:*:*:*:*:*:*
cpe:2.3:a:softing:secure_integration_server:*:*:*:*:*:*:*:*
Vendors & Products Softing
Softing edgeaggregator
Softing edgeconnector
Softing secure Integration Server

Subscriptions

Softing Edgeaggregator Edgeconnector Secure Integration Server
cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2024-08-02T12:09:43.421Z

Reserved: 2023-02-28T17:58:45.479Z

Link: CVE-2023-27336

cve-icon Vulnrichment

Updated: 2024-08-02T12:09:43.421Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-03T02:15:10.807

Modified: 2025-08-13T00:04:00.463

Link: CVE-2023-27336

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses