PT-2022-26002 · Heidenhain · Heidenhain Controller Tnc 640
Marco Balduzzi
·
Published
2022-10-28
·
Updated
2025-10-13
·
CVE-2022-41648
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HEIDENHAIN Controller TNC 640 version 340590 07 SP5
Description
The issue is related to improper authentication, which may allow an attacker to deny service to the production line, steal sensitive data from the production line, and alter any products created by the production line.
Recommendations
For version 340590 07 SP5, consider temporarily restricting access to the system until a patch or fix is available to prevent potential exploitation of the improper authentication issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Heidenhain Controller Tnc 640