Siemens SINUMERIK Integrate Operate Clients between 2.0.3.00.016 (including) and 2.0.6 (excluding) and between 3.0.4.00.032 (including) and 3.0.6 (excluding) contain a vulnerability that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack.
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/96519 | third party advisory vdb entry |
http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-934525.pdf | vendor advisory |