Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Siemens. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of OPC UA ConditionRefresh requests. By sending a large number of requests, an attacker can consume all available resources on the server. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-20498.
History

Wed, 13 Aug 2025 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Softing
Softing edgeaggregator
Softing edgeconnector
Softing opc Ua C\+\+ Software Development Kit
Softing secure Integration Server
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:softing:edgeaggregator:*:*:*:*:*:*:*:*
cpe:2.3:a:softing:edgeconnector:*:*:*:*:*:*:*:*
cpe:2.3:a:softing:opc_ua_c\+\+_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:softing:secure_integration_server:*:*:*:*:*:*:*:*
Vendors & Products Softing
Softing edgeaggregator
Softing edgeconnector
Softing opc Ua C\+\+ Software Development Kit
Softing secure Integration Server

cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published: 2024-05-03T01:55:56.942Z

Updated: 2024-08-02T12:09:43.393Z

Reserved: 2023-02-28T17:58:45.479Z

Link: CVE-2023-27334

cve-icon Vulnrichment

Updated: 2024-08-02T12:09:43.393Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-03T02:15:10.443

Modified: 2025-08-13T00:10:16.497

Link: CVE-2023-27334

cve-icon Redhat

No data.