A vulnerability has been identified in SINUMERIK Analyse MyCondition (All versions), SINUMERIK Analyze MyPerformance (All versions), SINUMERIK Analyze MyPerformance /OEE-Monitor (All versions), SINUMERIK Analyze MyPerformance /OEE-Tuning (All versions), SINUMERIK Integrate Client 02 (All versions >= V02.00.12 < 02.00.18), SINUMERIK Integrate Client 03 (All versions >= V03.00.12 < 03.00.18), SINUMERIK Integrate Client 04 (V04.00.02 and all versions >= V04.00.15 < 04.00.18), SINUMERIK Integrate for Production 4.1 (All versions < V4.1 SP10 HF3), SINUMERIK Integrate for Production 5.1 (V5.1), SINUMERIK Manage MyMachines (All versions), SINUMERIK Manage MyMachines /Remote (All versions), SINUMERIK Manage MyMachines /Spindel Monitor (All versions), SINUMERIK Manage MyPrograms (All versions), SINUMERIK Manage MyResources /Programs (All versions), SINUMERIK Manage MyResources /Tools (All versions), SINUMERIK Manage MyTools (All versions), SINUMERIK Operate V4.8 (All versions < V4.8 SP8), SINUMERIK Operate V4.93 (All versions < V4.93 HF7), SINUMERIK Operate V4.94 (All versions < V4.94 HF5), SINUMERIK Optimize MyProgramming /NX-Cam Editor (All versions). Due to an error in a third-party dependency the ssl flags used for setting up a TLS connection to a server are overwitten with wrong settings. This results in a missing validation of the server certificate and thus in a possible TLS MITM szenario.
References
Link | Resource |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-729965.pdf | Vendor Advisory |
https://us-cert.cisa.gov/ics/advisories/icsa-21-194-04 | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
History
09 Aug 2021, 16:26
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
References | (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-729965.pdf - Vendor Advisory | |
CPE | cpe:2.3:h:siemens:sinumerik_operate:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_operate_firmware:4.93:hotfix_2:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_operate_firmware:4.8:sp4:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_operate_firmware:4.8:sp5:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_operate_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_operate_firmware:4.8:sp6:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_operate_firmware:4.93:-:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_operate_firmware:4.94:hotfix_3:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_integrate_client_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_operate_firmware:4.8:sp2:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_manage_myprograms_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_operate_firmware:4.93:hotfix_4:*:*:*:*:*:* cpe:2.3:h:siemens:sinumerik_manage_mymachines:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:sinumerik_analyse_mycondition:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_operate_firmware:4.8:-:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_operate_firmware:4.93:hotfix_3:*:*:*:*:*:* cpe:2.3:h:siemens:sinumerik_optimize_myprogramming:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_analyse_mycondition_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_operate_firmware:4.93:hotfix_5:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_operate_firmware:4.8:sp7:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_manage_myresources_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:sinumerik_manage_myresources:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_operate_firmware:4.93:hotfix_6:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_operate_firmware:4.93:hotfix_1:*:*:*:*:*:* cpe:2.3:h:siemens:sinumerik_integrate_client:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:sinumerik_manage_mytools:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_operate_firmware:4.8:sp1:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_operate_firmware:4.94:hotfix_2:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_operate_firmware:4.94:-:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_integrate_for_production_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_operate_firmware:4.94:hotfix_4:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_manage_mytools_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:sinumerik_analyze_myperformance:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:sinumerik_integrate_for_production:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_optimize_myprogramming_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_operate_firmware:4.8:sp3:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_integrate_for_production_firmware:5.1:*:*:*:*:*:*:* cpe:2.3:h:siemens:sinumerik_manage_myprograms:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_manage_mymachines_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_operate_firmware:4.94:hotfix_1:*:*:*:*:*:* cpe:2.3:o:siemens:sinumerik_analyze_myperformance_firmware:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : 5.8
v3 : 7.4 |
13 Jul 2021, 12:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-295 | |
Summary | A vulnerability has been identified in SINUMERIK Analyse MyCondition (All versions), SINUMERIK Analyze MyPerformance (All versions), SINUMERIK Analyze MyPerformance /OEE-Monitor (All versions), SINUMERIK Analyze MyPerformance /OEE-Tuning (All versions), SINUMERIK Integrate Client 02 (All versions >= V02.00.12 < 02.00.18), SINUMERIK Integrate Client 03 (All versions >= V03.00.12 < 03.00.18), SINUMERIK Integrate Client 04 (V04.00.02 and all versions >= V04.00.15 < 04.00.18), SINUMERIK Integrate for Production 4.1 (All versions < V4.1 SP10 HF3), SINUMERIK Integrate for Production 5.1 (V5.1), SINUMERIK Manage MyMachines (All versions), SINUMERIK Manage MyMachines /Remote (All versions), SINUMERIK Manage MyMachines /Spindel Monitor (All versions), SINUMERIK Manage MyPrograms (All versions), SINUMERIK Manage MyResources /Programs (All versions), SINUMERIK Manage MyResources /Tools (All versions), SINUMERIK Manage MyTools (All versions), SINUMERIK Operate V4.8 (All versions < V4.8 SP8), SINUMERIK Operate V4.93 (All versions < V4.93 HF7), SINUMERIK Operate V4.94 (All versions < V4.94 HF5), SINUMERIK Optimize MyProgramming /NX-Cam Editor (All versions). Due to an error in a third-party dependency the ssl flags used for setting up a TLS connection to a server are overwitten with wrong settings. This results in a missing validation of the server certificate and thus in a possible TLS MITM szenario. |
13 Jul 2021, 11:31
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-07-13 11:15
Updated : 2024-02-04 21:47
NVD link : CVE-2021-31892
Mitre link : CVE-2021-31892
CVE.ORG link : CVE-2021-31892
JSON object : View
Products Affected
siemens
- sinumerik_integrate_client
- sinumerik_manage_mymachines_firmware
- sinumerik_integrate_for_production_firmware
- sinumerik_analyse_mycondition_firmware
- sinumerik_manage_myprograms
- sinumerik_integrate_client_firmware
- sinumerik_operate_firmware
- sinumerik_integrate_for_production
- sinumerik_manage_myprograms_firmware
- sinumerik_operate
- sinumerik_analyse_mycondition
- sinumerik_analyze_myperformance_firmware
- sinumerik_manage_mymachines
- sinumerik_analyze_myperformance
- sinumerik_manage_myresources
- sinumerik_optimize_myprogramming
- sinumerik_manage_myresources_firmware
- sinumerik_manage_mytools_firmware
- sinumerik_optimize_myprogramming_firmware
- sinumerik_manage_mytools
CWE
CWE-295
Improper Certificate Validation