logo

OPC UA Deep Dive Series (Part 9): Chaining Vulnerabilities to Exploit Softing OPC UA Integration Server

ID: e3b37b11-9cd0-57c6-9af7-8c3a738eee79

STIX ID: report--e3b37b11-9cd0-57c6-9af7-8c3a738eee79

Feed Name: Claroty Team82

Threat Score
85/100

Date Published: 2024-01-30

Date Updated: 2026-04-17

Author: Uri Katz

...
...

Team82 provides a deep technical analysis and PoC of a chained set of vulnerabilities in Softing Secure Integration Server (and related products) that enable pre-auth remote code execution. The chain abuses OPC UA FileDirectory/FileType behaviors and address-space handling to assign filesystem paths and create files, and leverages an nginx/URI path-traversal to write arbitrary XML files, culminating in writing a DLL to C:\Windows\System32 and triggering WerFault to execute it; Softing has since released patches and advisories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.