← Back

CVE-2021-31892

nvd nist
Published: Jul 13, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.4
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.2 / Impact: 5.2
Source: NVD

Description

A vulnerability has been identified in SINUMERIK Analyse MyCondition (All versions), SINUMERIK Analyze MyPerformance (All versions), SINUMERIK Analyze MyPerformance /OEE-Monitor (All versions), SINUMERIK Analyze MyPerformance /OEE-Tuning (All versions), SINUMERIK Integrate Client 02 (All versions >= V02.00.12 < 02.00.18), SINUMERIK Integrate Client 03 (All versions >= V03.00.12 < 03.00.18), SINUMERIK Integrate Client 04 (V04.00.02 and all versions >= V04.00.15 < 04.00.18), SINUMERIK Integrate for Production 4.1 (All versions < V4.1 SP10 HF3), SINUMERIK Integrate for Production 5.1 (V5.1), SINUMERIK Manage MyMachines (All versions), SINUMERIK Manage MyMachines /Remote (All versions), SINUMERIK Manage MyMachines /Spindel Monitor (All versions), SINUMERIK Manage MyPrograms (All versions), SINUMERIK Manage MyResources /Programs (All versions), SINUMERIK Manage MyResources /Tools (All versions), SINUMERIK Manage MyTools (All versions), SINUMERIK Operate V4.8 (All versions < V4.8 SP8), SINUMERIK Operate V4.93 (All versions < V4.93 HF7), SINUMERIK Operate V4.94 (All versions < V4.94 HF5), SINUMERIK Optimize MyProgramming /NX-Cam Editor (All versions). Due to an error in a third-party dependency the ssl flags used for setting up a TLS connection to a server are overwitten with wrong settings. This results in a missing validation of the server certificate and thus in a possible TLS MITM szenario.

Affected (33)

10 products
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Sinumerik Analyse Mycondition
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Sinumerik Analyze Myperformance
All versions
Configuration C
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Siemens
From 2.00.12 to 2.00.18
From 3.00.12 to 3.00.18
From 4.00.15 to 4.00.18
Running on/withPlatform Versions
Siemens
Sinumerik Integrate Client
All versions
Configuration D
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Siemens
Up to 4.1
Version 5.1
Running on/withPlatform Versions
Siemens
Sinumerik Integrate For Production
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Sinumerik Manage Mymachines
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Sinumerik Manage Myprograms
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Sinumerik Manage Myresources
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Sinumerik Manage Mytools
All versions
Configuration I
21 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Siemens
Before 4.8
Version 4.8
Version 4.8 sp1
Version 4.8 sp2
Version 4.8 sp3
Version 4.8 sp4
Version 4.8 sp5
Version 4.8 sp6
Version 4.8 sp7
Version 4.93
Version 4.93 hotfix_1
Version 4.93 hotfix_2
Version 4.93 hotfix_3
Version 4.93 hotfix_4
Version 4.93 hotfix_5
Version 4.93 hotfix_6
Version 4.94
Version 4.94 hotfix_1
Version 4.94 hotfix_2
Version 4.94 hotfix_3
Version 4.94 hotfix_4
Running on/withPlatform Versions
Siemens
Sinumerik Operate
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Sinumerik Optimize Myprogramming
All versions

References (4)

Source: productcert@siemens.com
Vendor Advisory
Source: productcert@siemens.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.