PT-2017-17388 · Siemens · Siemens Ozw672+1

Published

2017-08-08

·

Updated

2019-10-09

·

CVE-2017-6873

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Siemens OZW672 (all versions) Siemens OZW772 (all versions)
Description A vulnerability was discovered that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack on the integrated web server on port 443/tcp.
Recommendations For Siemens OZW672 (all versions), restrict access to the integrated web server on port 443/tcp to minimize the risk of exploitation. For Siemens OZW772 (all versions), restrict access to the integrated web server on port 443/tcp to minimize the risk of exploitation.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6873

Affected Products

Siemens Ozw672
Siemens Ozw772