PT-2021-19567 · Siemens · Sinumerik Integrate Client 04+19
Published
2021-07-13
·
Updated
2021-08-09
·
CVE-2021-31892
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
SINUMERIK Analyse MyCondition versions all
SINUMERIK Analyze MyPerformance versions all
SINUMERIK Analyze MyPerformance /OEE-Monitor versions all
SINUMERIK Analyze MyPerformance /OEE-Tuning versions all
SINUMERIK Integrate Client 02 versions 02.00.12 through 02.00.17
SINUMERIK Integrate Client 03 versions 03.00.12 through 03.00.17
SINUMERIK Integrate Client 04 versions 04.00.02, 04.00.15 through 04.00.17
SINUMERIK Integrate for Production 4.1 versions prior to 4.1 SP10 HF3
SINUMERIK Integrate for Production 5.1 version 5.1
SINUMERIK Manage MyMachines versions all
SINUMERIK Manage MyMachines /Remote versions all
SINUMERIK Manage MyMachines /Spindel Monitor versions all
SINUMERIK Manage MyPrograms versions all
SINUMERIK Manage MyResources /Programs versions all
SINUMERIK Manage MyResources /Tools versions all
SINUMERIK Manage MyTools versions all
SINUMERIK Operate V4.8 versions prior to 4.8 SP8
SINUMERIK Operate V4.93 versions prior to 4.93 HF7
SINUMERIK Operate V4.94 versions prior to 4.94 HF5
SINUMERIK Optimize MyProgramming /NX-Cam Editor versions all
Description:
A vulnerability has been identified due to an error in a third-party dependency. The ssl flags used for setting up a TLS connection to a server are overwritten with wrong settings, resulting in a missing validation of the server certificate. This leads to a possible TLS MITM scenario.
Recommendations:
SINUMERIK Analyse MyCondition: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SINUMERIK Analyze MyPerformance: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SINUMERIK Analyze MyPerformance /OEE-Monitor: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SINUMERIK Analyze MyPerformance /OEE-Tuning: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SINUMERIK Integrate Client 02: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SINUMERIK Integrate Client 03: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SINUMERIK Integrate Client 04: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SINUMERIK Integrate for Production 4.1: Update to version 4.1 SP10 HF3 or later.
SINUMERIK Integrate for Production 5.1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SINUMERIK Manage MyMachines: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SINUMERIK Manage MyMachines /Remote: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SINUMERIK Manage MyMachines /Spindel Monitor: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SINUMERIK Manage MyPrograms: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SINUMERIK Manage MyResources /Programs: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SINUMERIK Manage MyResources /Tools: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SINUMERIK Manage MyTools: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SINUMERIK Operate V4.8: Update to version 4.8 SP8 or later.
SINUMERIK Operate V4.93: Update to version 4.93 HF7 or later.
SINUMERIK Operate V4.94: Update to version 4.94 HF5 or later.
SINUMERIK Optimize MyProgramming /NX-Cam Editor: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sinumerik Analyse Mycondition
Sinumerik Analyze Myperformance
Sinumerik Analyze Myperformance /Oee-Monitor
Sinumerik Analyze Myperformance /Oee-Tuning
Sinumerik Integrate Client 02
Sinumerik Integrate Client 03
Sinumerik Integrate Client 04
Sinumerik Integrate For Production 4.1
Sinumerik Integrate For Production 5.1
Sinumerik Manage Mymachines
Sinumerik Manage Mymachines /Remote
Sinumerik Manage Mymachines /Spindel Monitor
Sinumerik Manage Myprograms
Sinumerik Manage Myresources /Programs
Sinumerik Manage Myresources /Tools
Sinumerik Manage Mytools
Sinumerik Operate V4.8
Sinumerik Operate V4.93
Sinumerik Operate V4.94
Sinumerik Optimize Myprogramming /Nx-Cam Editor