PT-2021-19567 · Siemens · Sinumerik Integrate Client 04+19

Published

2021-07-13

·

Updated

2021-08-09

·

CVE-2021-31892

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: SINUMERIK Analyse MyCondition versions all SINUMERIK Analyze MyPerformance versions all SINUMERIK Analyze MyPerformance /OEE-Monitor versions all SINUMERIK Analyze MyPerformance /OEE-Tuning versions all SINUMERIK Integrate Client 02 versions 02.00.12 through 02.00.17 SINUMERIK Integrate Client 03 versions 03.00.12 through 03.00.17 SINUMERIK Integrate Client 04 versions 04.00.02, 04.00.15 through 04.00.17 SINUMERIK Integrate for Production 4.1 versions prior to 4.1 SP10 HF3 SINUMERIK Integrate for Production 5.1 version 5.1 SINUMERIK Manage MyMachines versions all SINUMERIK Manage MyMachines /Remote versions all SINUMERIK Manage MyMachines /Spindel Monitor versions all SINUMERIK Manage MyPrograms versions all SINUMERIK Manage MyResources /Programs versions all SINUMERIK Manage MyResources /Tools versions all SINUMERIK Manage MyTools versions all SINUMERIK Operate V4.8 versions prior to 4.8 SP8 SINUMERIK Operate V4.93 versions prior to 4.93 HF7 SINUMERIK Operate V4.94 versions prior to 4.94 HF5 SINUMERIK Optimize MyProgramming /NX-Cam Editor versions all
Description: A vulnerability has been identified due to an error in a third-party dependency. The ssl flags used for setting up a TLS connection to a server are overwritten with wrong settings, resulting in a missing validation of the server certificate. This leads to a possible TLS MITM scenario.
Recommendations: SINUMERIK Analyse MyCondition: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SINUMERIK Analyze MyPerformance: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SINUMERIK Analyze MyPerformance /OEE-Monitor: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SINUMERIK Analyze MyPerformance /OEE-Tuning: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SINUMERIK Integrate Client 02: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SINUMERIK Integrate Client 03: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SINUMERIK Integrate Client 04: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SINUMERIK Integrate for Production 4.1: Update to version 4.1 SP10 HF3 or later. SINUMERIK Integrate for Production 5.1: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SINUMERIK Manage MyMachines: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SINUMERIK Manage MyMachines /Remote: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SINUMERIK Manage MyMachines /Spindel Monitor: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SINUMERIK Manage MyPrograms: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SINUMERIK Manage MyResources /Programs: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SINUMERIK Manage MyResources /Tools: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SINUMERIK Manage MyTools: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SINUMERIK Operate V4.8: Update to version 4.8 SP8 or later. SINUMERIK Operate V4.93: Update to version 4.93 HF7 or later. SINUMERIK Operate V4.94: Update to version 4.94 HF5 or later. SINUMERIK Optimize MyProgramming /NX-Cam Editor: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-31892

Affected Products

Sinumerik Analyse Mycondition
Sinumerik Analyze Myperformance
Sinumerik Analyze Myperformance /Oee-Monitor
Sinumerik Analyze Myperformance /Oee-Tuning
Sinumerik Integrate Client 02
Sinumerik Integrate Client 03
Sinumerik Integrate Client 04
Sinumerik Integrate For Production 4.1
Sinumerik Integrate For Production 5.1
Sinumerik Manage Mymachines
Sinumerik Manage Mymachines /Remote
Sinumerik Manage Mymachines /Spindel Monitor
Sinumerik Manage Myprograms
Sinumerik Manage Myresources /Programs
Sinumerik Manage Myresources /Tools
Sinumerik Manage Mytools
Sinumerik Operate V4.8
Sinumerik Operate V4.93
Sinumerik Operate V4.94
Sinumerik Optimize Myprogramming /Nx-Cam Editor