PT-2017-15472 · Siemens · Sinumerik Integrate Operate Clients

Publicado

2017-03-01

·

Atualizado

2019-10-09

·

CVE-2017-2685

CVSS v3.1

7.4

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Siemens SINUMERIK Integrate Operate Clients versions 2.0.3.00.016 through 2.0.6 Siemens SINUMERIK Integrate Operate Clients versions 3.0.4.00.032 through 3.0.6
Description The issue allows an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack.
Recommendations For versions 2.0.3.00.016 through 2.0.6, update to a version outside of this range to resolve the issue. For versions 3.0.4.00.032 through 3.0.6, update to a version outside of this range to resolve the issue.

Correção

Information Disclosure

Protection Mechanism Failure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-2685

Produtos afetados

Sinumerik Integrate Operate Clients