PT-2025-28372 · Siemens · Sicam Toolbox Ii
Published
2025-07-08
·
Updated
2025-07-08
·
CVE-2024-31853
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
SICAM TOOLBOX II versions prior to V07.11
Description:
A issue has been identified in the application where it fails to check the extended key usage attribute of a device's certificate when establishing an HTTPS connection to the TLS server of a managed device. This could allow an attacker to execute an on-path network attack, also known as a man-in-the-middle (MitM) attack.
Recommendations:
For versions prior to V07.11, update to version V07.11 or later to resolve the issue. As a temporary workaround, consider restricting access to the TLS server of managed devices until the update is applied. Avoid using the affected application to establish HTTPS connections to devices with unverified certificates.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sicam Toolbox Ii