« Volver al listado

CVE-2022-37453

Estado: ModificadaAlta (7.5)—

An issue was discovered in Softing OPC UA C++ SDK before 6.10. A buffer overflow or an excess allocation happens due to unchecked array and matrix bounds in structure data types.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (6)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-37453",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-37453",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-08T18:57:43.699381Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-10-20T21:15:10.107",
  "references": [
    {
      "url": "https://industrial.softing.com/fileadmin/psirt/downloads/syt-2022-9.html",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://softing.com",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://industrial.softing.com/fileadmin/psirt/downloads/syt-2022-9.html",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://softing.com",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in Softing OPC UA C++ SDK before 6.10. A buffer overflow or an excess allocation happens due to unchecked array and matrix bounds in structure data types."
    },
    {
      "lang": "es",
      "value": "Se ha detectado un problema en Softing OPC UA C++ SDK versiones anteriores a 6.10. Es producido un desbordamiento del búfer o un exceso de asignación debido a los límites de matrices y arrays no comprobados en los tipos de datos de estructuras"
    }
  ],
  "lastModified": "2026-06-17T04:55:07.197",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:softing:edgeaggregator:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "628CF1AA-0EAA-4638-9B55-D805F48FE6C0",
              "versionEndIncluding": "3.50"
            },
            {
              "criteria": "cpe:2.3:a:softing:edgeconnector:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "74EEA0E5-E594-4B2F-A7B9-8A3D592F6192",
              "versionEndIncluding": "3.50"
            },
            {
              "criteria": "cpe:2.3:a:softing:opc:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C23CF12C-EE3C-46AF-A153-4F9EC85A3417",
              "versionEndIncluding": "5.22"
            },
            {
              "criteria": "cpe:2.3:a:softing:opc_ua_c\\+\\+_software_development_kit:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE20E08D-5FD6-43CD-8405-925224096751",
              "versionEndIncluding": "6.00"
            },
            {
              "criteria": "cpe:2.3:a:softing:secure_integration_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "788D765F-4A20-49CC-BC97-483E69AB63C7",
              "versionEndIncluding": "1.22"
            },
            {
              "criteria": "cpe:2.3:a:softing:uagates:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA389737-C787-47B1-ABB7-95AE945BDB6B",
              "versionEndIncluding": "1.74"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}