PT-2025-28373 · Siemens · Sicam Toolbox Ii
Published
2025-07-08
·
Updated
2025-07-08
·
CVE-2024-31854
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
SICAM TOOLBOX II versions prior to V07.11
Description:
A issue has been identified in the application where it fails to compare the common name of a device's certificate with an expected value when establishing an HTTPS connection to the TLS server of a managed device. This could allow an attacker to execute an on-path network attack, also known as a man-in-the-middle (MitM) attack.
Recommendations:
For versions prior to V07.11, update to version V07.11 or later to resolve the issue. As a temporary workaround, consider restricting access to the TLS server of managed devices to minimize the risk of exploitation. Avoid using the affected application to establish HTTPS connections to untrusted devices until the issue is resolved.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sicam Toolbox Ii