TLS Certificate Validation Flaw in SICAM TOOLBOX II from Siemens
CVE-2024-31853

7.7HIGH

Key Information:

Vendor

Siemens

Vendor
CVE Published:
8 July 2025

What is CVE-2024-31853?

A vulnerability exists in SICAM TOOLBOX II that stems from a lack of validation for the extended key usage attribute in the TLS server's certificate during HTTPS connections. This oversight may allow attackers to execute an on-path network attack, compromising data integrity and confidentiality by intercepting communication between the application and managed devices. Users of affected versions should assess their exposure and implement recommended security measures.

Affected Version(s)

SICAM TOOLBOX II 0

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-31853 : TLS Certificate Validation Flaw in SICAM TOOLBOX II from Siemens