QID 591231
Date Published: 2022-12-16
QID 591231: Siemens SINUMERIK ONE and SINUMERIK MC Insufficiently Protected Credentials Vulnerability (ICSA-22-314-04, ssa-568428)
AFFECTED PRODUCTS
The following versions of SINUMERIK CNC systems are affected:
SINUMERIK ONE All Versions
SINUMERIK MC All Versions
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
Successful exploitation of this vulnerability could allow attackers to discover the private key of a given CPU product family via an offline attack against a single CPU from the family. Attackers could then use this knowledge to extract confidential configuration data from projects.
Solution
Customers are advised to refer to CERT MITIGATIONS section icsa-22-314-04 for affected packages and patching details.
Vendor References
- icsa-22-314-04 -
www.cisa.gov/uscert/ics/advisories/icsa-22-314-04
CVEs related to QID 591231
Software Advisories
| Advisory ID | Software | Component | Link |
|---|