TLS Certificate Validation Flaw in Industrial Edge Management by Siemens
CVE-2022-40147

7.4HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
11 October 2022

Summary

A vulnerability has been identified in the Industrial Edge Management software by Siemens, where it fails to properly validate the server certificate when establishing a TLS connection. This oversight can enable an attacker to spoof a trusted entity, potentially compromising communication between clients and servers. Users running versions prior to V1.5.1 are at risk, as this could allow unauthorized access and manipulation of sensitive data during transmission.

Affected Version(s)

Industrial Edge Management All versions < V1.5.1

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.