CVE-2021-31892
Published: Jul 13, 2021
Modified: Aug 3, 2024
Description
A vulnerability has been identified in SINUMERIK Analyse MyCondition (All versions), SINUMERIK Analyze MyPerformance (All versions), SINUMERIK Analyze MyPerformance /OEE-Monitor (All versions), SINUMERIK Analyze MyPerformance /OEE-Tuning (All versions), SINUMERIK Integrate Client 02 (All versions >= V02.00.12 < 02.00.18), SINUMERIK Integrate Client 03 (All versions >= V03.00.12 < 03.00.18), SINUMERIK Integrate Client 04 (V04.00.02 and all versions >= V04.00.15 < 04.00.18), SINUMERIK Integrate for Production 4.1 (All versions < V4.1 SP10 HF3), SINUMERIK Integrate for Production 5.1 (V5.1), SINUMERIK Manage MyMachines (All versions), SINUMERIK Manage MyMachines /Remote (All versions), SINUMERIK Manage MyMachines /Spindel Monitor (All versions), SINUMERIK Manage MyPrograms (All versions), SINUMERIK Manage MyResources /Programs (All versions), SINUMERIK Manage MyResources /Tools (All versions), SINUMERIK Manage MyTools (All versions), SINUMERIK Operate V4.8 (All versions < V4.8 SP8), SINUMERIK Operate V4.93 (All versions < V4.93 HF7), SINUMERIK Operate V4.94 (All versions < V4.94 HF5), SINUMERIK Optimize MyProgramming /NX-Cam Editor (All versions). Due to an error in a third-party dependency the ssl flags used for setting up a TLS connection to a server are overwitten with wrong settings. This results in a missing validation of the server certificate and thus in a possible TLS MITM szenario.
| Vendor | Product | Versions |
|---|---|---|
Siemens | SINUMERIK Analyse MyCondition | affected All versions |
Siemens | SINUMERIK Analyze MyPerformance | affected All versions |
Siemens | SINUMERIK Analyze MyPerformance /OEE-Monitor | affected All versions |
Siemens | SINUMERIK Analyze MyPerformance /OEE-Tuning | affected All versions |
Siemens | SINUMERIK Integrate Client 02 | affected All versions >= V02.00.12 < 02.00.18 |
Siemens | SINUMERIK Integrate Client 03 | affected All versions >= V03.00.12 < 03.00.18 |
Siemens | SINUMERIK Integrate Client 04 | affected V04.00.02 and all versions >= V04.00.15 < 04.00.18 |
Siemens | SINUMERIK Integrate for Production 4.1 | affected All versions < V4.1 SP10 HF3 |
Siemens | SINUMERIK Integrate for Production 5.1 | affected V5.1 |
Siemens | SINUMERIK Manage MyMachines | affected All versions |
Siemens | SINUMERIK Manage MyMachines /Remote | affected All versions |
Siemens | SINUMERIK Manage MyMachines /Spindel Monitor | affected All versions |
Siemens | SINUMERIK Manage MyPrograms | affected All versions |
Siemens | SINUMERIK Manage MyResources /Programs | affected All versions |
Siemens | SINUMERIK Manage MyResources /Tools | affected All versions |
Siemens | SINUMERIK Manage MyTools | affected All versions |
Siemens | SINUMERIK Operate V4.8 | affected All versions < V4.8 SP8 |
Siemens | SINUMERIK Operate V4.93 | affected All versions < V4.93 HF7 |
Siemens | SINUMERIK Operate V4.94 | affected All versions < V4.94 HF5 |
Siemens | SINUMERIK Optimize MyProgramming /NX-Cam Editor | affected All versions |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now