Softing Secure Integration Server V1.22 is vulnerable to...
Moderate severity
Unreviewed
Published
Aug 18, 2022
to the GitHub Advisory Database
•
Updated Jan 31, 2023
Description
Published by the National Vulnerability Database
Aug 17, 2022
Published to the GitHub Advisory Database
Aug 18, 2022
Last updated
Jan 31, 2023
Softing Secure Integration Server V1.22 is vulnerable to authentication bypass via a machine-in-the-middle attack. The default the administration interface is accessible via plaintext HTTP protocol, facilitating the attack. The HTTP request may contain the session cookie in the request, which may be captured for use in authenticating to the server.
References