{
  "document": {
    "aggregate_severity": {
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "The information provided in this disclosure is provided \"as is\" without warranty of any kind.\nSofting disclaims all warranties, either express or implied, including the warranties of\nmerchantability and fitness for a particular purpose. In no event shall Softing or its suppliers be\nliable for any damages whatsoever including direct, indirect, incidental, consequential, loss of\nbusiness profits or special damages, even if Softing or its suppliers have been advised of the\npossibility of such damages.\nSome states do not allow the exclusion or limitation of liability for consequential or incidental\ndamages so the foregoing limitation may not apply.\n",
        "title": "Disclaimer"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "Softing PSIRT - contact us at psirt@softing.com",
      "name": "Softing",
      "namespace": "https://industrial.softing.com"
    },
    "source_lang": "en-US",
    "title": "JavaScript vulnerability in edgeConnector and edgeAggregator",
    "tracking": {
      "current_release_date": "2026-03-18T11:00:00.000Z",
      "generator": {
        "date": "2026-03-17T14:09:57.035Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.5.45"
        }
      },
      "id": "SYT-2024-3",
      "initial_release_date": "2026-03-17T23:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-03-17T23:00:00.000Z",
          "number": "1.0.0",
          "summary": "Final version"
        }
      ],
      "status": "final",
      "version": "1.0.0"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "product_version",
        "name": "Softing edgeConnector = V3.80",
        "product": {
          "name": "Softing edgeConnector V3.80",
          "product_id": "CSAFPID-0001"
        }
      },
      {
        "category": "product_version",
        "name": "Softing edgeAggregator = V3.80",
        "product": {
          "name": "Softing edgeAggregator V3.80",
          "product_id": "CSAFPID-0002"
        }
      },
      {
        "category": "product_version",
        "name": "Softing edgeConnector = V2024.01",
        "product": {
          "name": "Softing edgeConnector V2024.01 (successor of V4.00)",
          "product_id": "CSAFPID-0101"
        }
      },
      {
        "category": "product_version",
        "name": "Softing edgeAggregator = V2024.01",
        "product": {
          "name": "Softing edgeAggregator V2024.01 (successor of V4.00)",
          "product_id": "CSAFPID-0102"
        }
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-46233",
      "cwe": {
        "id": "CWE-328",
        "name": "Use of Weak Hash"
      },
      "discovery_date": "2023-02-15T10:00:00.000Z",
      "notes": [
        {
          "category": "other",
          "text": "Solution: Update of corresponding components required"
        },
        {
          "category": "summary",
          "text": "crypto-js PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-0101",
          "CSAFPID-0102"
        ],
        "known_affected": [
          "CSAFPID-0001",
          "CSAFPID-0002"
        ]
      },
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.1,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 9.1,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0001",
            "CSAFPID-0002"
          ]
        }
      ]
    }
  ]
}