Executive brief
Softing smartLink HW-PN is an industrial networking device used to link control systems and devices on a network. A memory leak in its scan method can cause resource exhaustion and performance degradation over time, potentially leading to system instability or denial of service if the device runs out of available memory.
Technical details
This vulnerability is a CWE-401 missing release of memory after effective lifetime issue in the scan method of smartLink HW-PN. The flaw allows accumulated memory allocation without proper deallocation, leading to resource leak exposure. The vulnerability is exploitable via the network with LOW attack complexity and requires LOW privileges; no user interaction is needed. An authenticated attacker can trigger memory exhaustion, causing secondary integrity and availability impacts (system instability, service degradation). Patch is available in version 1.10 and later.
Affected products
- Softing smartLink HW-PN 1.04 before 1.10
Timeline
- 2026-09-04: disclosed