Exploitation Summary
EIP tracks 1 public exploit for CVE-2022-2334.
PoCs published by Chris Anastasio (muffin) of Incite Team, Steven Seeley (mr_me) of Incite Team, including Metasploit module exploits/windows/http/softing_sis_rce.
AI-analyzed exploit summary This Metasploit module exploits CVE-2022-1373 and CVE-2022-2334 to achieve authenticated RCE on Softing Secure Integration Server v1.22 via directory traversal and DLL hijacking.
Description
The application searches for a library dll that is not found. If an attacker can place a dll with this name, then the attacker can leverage it to execute arbitrary code on the targeted Softing Secure Integration Server V1.22.
Exploits (1)
This Metasploit module exploits CVE-2022-1373 and CVE-2022-2334 to achieve authenticated RCE on Softing Secure Integration Server v1.22 via directory traversal and DLL hijacking.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H