PT-2021-23478 · Siemens · Sinumerik Edge

Published

2021-12-14

·

Updated

2021-12-20

·

CVE-2021-42027

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SINUMERIK Edge versions prior to V3.2
Description A security issue has been identified where the affected software fails to properly validate the server certificate when establishing a TLS connection. This could enable an attacker to impersonate a trusted entity by interfering with the communication between the client and the intended server.
Recommendations For SINUMERIK Edge versions prior to V3.2, update to version V3.2 or later to resolve the issue. As a temporary workaround, consider restricting TLS connections to trusted servers or implementing additional validation measures for server certificates until a patch is available.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42027

Affected Products

Sinumerik Edge