CVE Database
/

CVE-2021-31892

Back to search

CVE-2021-31892

Published: Jul 13, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

A vulnerability has been identified in SINUMERIK Analyse MyCondition (All versions), SINUMERIK Analyze MyPerformance (All versions), SINUMERIK Analyze MyPerformance /OEE-Monitor (All versions), SINUMERIK Analyze MyPerformance /OEE-Tuning (All versions), SINUMERIK Integrate Client 02 (All versions >= V02.00.12 < 02.00.18), SINUMERIK Integrate Client 03 (All versions >= V03.00.12 < 03.00.18), SINUMERIK Integrate Client 04 (V04.00.02 and all versions >= V04.00.15 < 04.00.18), SINUMERIK Integrate for Production 4.1 (All versions < V4.1 SP10 HF3), SINUMERIK Integrate for Production 5.1 (V5.1), SINUMERIK Manage MyMachines (All versions), SINUMERIK Manage MyMachines /Remote (All versions), SINUMERIK Manage MyMachines /Spindel Monitor (All versions), SINUMERIK Manage MyPrograms (All versions), SINUMERIK Manage MyResources /Programs (All versions), SINUMERIK Manage MyResources /Tools (All versions), SINUMERIK Manage MyTools (All versions), SINUMERIK Operate V4.8 (All versions < V4.8 SP8), SINUMERIK Operate V4.93 (All versions < V4.93 HF7), SINUMERIK Operate V4.94 (All versions < V4.94 HF5), SINUMERIK Optimize MyProgramming /NX-Cam Editor (All versions). Due to an error in a third-party dependency the ssl flags used for setting up a TLS connection to a server are overwitten with wrong settings. This results in a missing validation of the server certificate and thus in a possible TLS MITM szenario.

VendorProductVersions

Siemens

SINUMERIK Analyse MyCondition

affected
All versions

Siemens

SINUMERIK Analyze MyPerformance

affected
All versions

Siemens

SINUMERIK Analyze MyPerformance /OEE-Monitor

affected
All versions

Siemens

SINUMERIK Analyze MyPerformance /OEE-Tuning

affected
All versions

Siemens

SINUMERIK Integrate Client 02

affected
All versions >= V02.00.12 < 02.00.18

Siemens

SINUMERIK Integrate Client 03

affected
All versions >= V03.00.12 < 03.00.18

Siemens

SINUMERIK Integrate Client 04

affected
V04.00.02 and all versions >= V04.00.15 < 04.00.18

Siemens

SINUMERIK Integrate for Production 4.1

affected
All versions < V4.1 SP10 HF3

Siemens

SINUMERIK Integrate for Production 5.1

affected
V5.1

Siemens

SINUMERIK Manage MyMachines

affected
All versions

Siemens

SINUMERIK Manage MyMachines /Remote

affected
All versions

Siemens

SINUMERIK Manage MyMachines /Spindel Monitor

affected
All versions

Siemens

SINUMERIK Manage MyPrograms

affected
All versions

Siemens

SINUMERIK Manage MyResources /Programs

affected
All versions

Siemens

SINUMERIK Manage MyResources /Tools

affected
All versions

Siemens

SINUMERIK Manage MyTools

affected
All versions

Siemens

SINUMERIK Operate V4.8

affected
All versions < V4.8 SP8

Siemens

SINUMERIK Operate V4.93

affected
All versions < V4.93 HF7

Siemens

SINUMERIK Operate V4.94

affected
All versions < V4.94 HF5

Siemens

SINUMERIK Optimize MyProgramming /NX-Cam Editor

affected
All versions

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now