CVE-2021-31892
7.4
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.2 / Impact: 5.2
Source: NVD
Description
A vulnerability has been identified in SINUMERIK Analyse MyCondition (All versions), SINUMERIK Analyze MyPerformance (All versions), SINUMERIK Analyze MyPerformance /OEE-Monitor (All versions), SINUMERIK Analyze MyPerformance /OEE-Tuning (All versions), SINUMERIK Integrate Client 02 (All versions >= V02.00.12 < 02.00.18), SINUMERIK Integrate Client 03 (All versions >= V03.00.12 < 03.00.18), SINUMERIK Integrate Client 04 (V04.00.02 and all versions >= V04.00.15 < 04.00.18), SINUMERIK Integrate for Production 4.1 (All versions < V4.1 SP10 HF3), SINUMERIK Integrate for Production 5.1 (V5.1), SINUMERIK Manage MyMachines (All versions), SINUMERIK Manage MyMachines /Remote (All versions), SINUMERIK Manage MyMachines /Spindel Monitor (All versions), SINUMERIK Manage MyPrograms (All versions), SINUMERIK Manage MyResources /Programs (All versions), SINUMERIK Manage MyResources /Tools (All versions), SINUMERIK Manage MyTools (All versions), SINUMERIK Operate V4.8 (All versions < V4.8 SP8), SINUMERIK Operate V4.93 (All versions < V4.93 HF7), SINUMERIK Operate V4.94 (All versions < V4.94 HF5), SINUMERIK Optimize MyProgramming /NX-Cam Editor (All versions). Due to an error in a third-party dependency the ssl flags used for setting up a TLS connection to a server are overwitten with wrong settings. This results in a missing validation of the server certificate and thus in a possible TLS MITM szenario.
Affected (33)
Products: Siemens: Sinumerik Analyse Mycondition Firmware, Sinumerik Analyze Myperformance Firmware, Sinumerik Integrate Client Firmware, Sinumerik Integrate For Production Firmware, Sinumerik Manage Mymachines Firmware, Sinumerik Manage Myprograms Firmware, Sinumerik Manage Myresources Firmware, Sinumerik Manage Mytools Firmware, Sinumerik Operate Firmware, Sinumerik Optimize Myprogramming Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinumerik Analyse Mycondition | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinumerik Analyze Myperformance | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.00.12 to 2.00.18 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinumerik Integrate Client | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinumerik Integrate For Production | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinumerik Manage Mymachines | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinumerik Manage Myprograms | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinumerik Manage Myresources | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinumerik Manage Mytools | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.8 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinumerik Operate | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinumerik Optimize Myprogramming | All versions |
References (4)
Source: productcert@siemens.com
Vendor Advisory
Source: productcert@siemens.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.