PT-2025-28373 · Siemens · Sicam Toolbox Ii

Published

2025-07-08

·

Updated

2025-07-08

·

CVE-2024-31854

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SICAM TOOLBOX II versions prior to V07.11
Description: A issue has been identified in the application where it fails to compare the common name of a device's certificate with an expected value when establishing an HTTPS connection to the TLS server of a managed device. This could allow an attacker to execute an on-path network attack, also known as a man-in-the-middle (MitM) attack.
Recommendations: For versions prior to V07.11, update to version V07.11 or later to resolve the issue. As a temporary workaround, consider restricting access to the TLS server of managed devices to minimize the risk of exploitation. Avoid using the affected application to establish HTTPS connections to untrusted devices until the issue is resolved.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-08543
CVE-2024-31854

Affected Products

Sicam Toolbox Ii