PT-2021-23478 · Siemens · Sinumerik Edge
Published
2021-12-14
·
Updated
2021-12-20
·
CVE-2021-42027
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SINUMERIK Edge versions prior to V3.2
Description
A security issue has been identified where the affected software fails to properly validate the server certificate when establishing a TLS connection. This could enable an attacker to impersonate a trusted entity by interfering with the communication between the client and the intended server.
Recommendations
For SINUMERIK Edge versions prior to V3.2, update to version V3.2 or later to resolve the issue. As a temporary workaround, consider restricting TLS connections to trusted servers or implementing additional validation measures for server certificates until a patch is available.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sinumerik Edge