CVE-2022-2336: Softing Edgeaggregator

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`. This allows Softing to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the `admin` password. There is no warning or prompt to ask the user to change the default password, and to change the password, many steps are required.

Affected products

  • Softing Edgeaggregator: version 3.1 only
  • Softing Edgeconnector: version 3.1 only
  • Softing Opc: version 5.2 only
  • Softing Opc Ua C++ Software Development Kit: version 6 only
  • Softing Secure Integration Server: version 1.22 only
  • Softing Uagates: version 1.74 only

Published 2022-08-17. Last modified 2026-06-17.