7.4
CVSSv3

CVE-2021-42027

Published: 14/12/2021 Updated: 20/12/2021
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.4 | Impact Score: 5.2 | Exploitability Score: 2.2
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

A vulnerability has been identified in SINUMERIK Edge (All versions < V3.2). The affected software does not properly validate the server certificate when initiating a TLS connection. This could allow an malicious user to spoof a trusted entity by interfering in the communication path between the client and the intended server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

siemens sinumerik edge

ICS Advisories

Siemens SINUMERIK Edge
Critical Infrastructure Sectors: Critical Manufacturing