TLS Certificate Validation Flaw in SICAM TOOLBOX II from Siemens
CVE-2024-31853
7.7HIGH
What is CVE-2024-31853?
A vulnerability exists in SICAM TOOLBOX II that stems from a lack of validation for the extended key usage attribute in the TLS server's certificate during HTTPS connections. This oversight may allow attackers to execute an on-path network attack, compromising data integrity and confidentiality by intercepting communication between the application and managed devices. Users of affected versions should assess their exposure and implement recommended security measures.
Affected Version(s)
SICAM TOOLBOX II 0