#VU66739 Improper Authentication in Softing AG products - CVE-2022-2336
Published: August 24, 2022 / Updated: August 24, 2022
Secure Integration Server
edgeConnector
edgeAggregator
Softing AG
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the affected software ships with the default administrator credentials as "admin" and password as "admin" and does not ask the user to change the password. A remote attacker can bypass authentication process and gain unauthorized access to the application.