← Security Alerts

CVE-2021-31892

Siemens · published 2021-07-13

Source record Collected from the National Vulnerability Database (NVD)

Description

Description by Siemens AG via the CVE Program.

A vulnerability has been identified in SINUMERIK Analyse MyCondition (All versions), SINUMERIK Analyze MyPerformance (All versions), SINUMERIK Analyze MyPerformance /OEE-Monitor (All versions), SINUMERIK Analyze MyPerformance /OEE-Tuning (All versions), SINUMERIK Integrate Client 02 (All versions >= V02.00.12 < 02.00.18), SINUMERIK Integrate Client 03 (All versions >= V03.00.12 < 03.00.18), SINUMERIK Integrate Client 04 (V04.00.02 and all versions >= V04.00.15 < 04.00.18), SINUMERIK Integrate for Production 4.1 (All versions < V4.1 SP10 HF3), SINUMERIK Integrate for Production 5.1 (V5.1), SINUMERIK Manage MyMachines (All versions), SINUMERIK Manage MyMachines /Remote (All versions), SINUMERIK Manage MyMachines /Spindel Monitor (All versions), SINUMERIK Manage MyPrograms (All versions), SINUMERIK Manage MyResources /Programs (All versions), SINUMERIK Manage MyResources /Tools (All versions), SINUMERIK Manage MyTools (All versions), SINUMERIK Operate V4.8 (All versions < V4.8 SP8), SINUMERIK Operate V4.93 (All versions < V4.93 HF7), SINUMERIK Operate V4.94 (All versions < V4.94 HF5), SINUMERIK Optimize MyProgramming /NX-Cam Editor (All versions). Due to an error in a third-party dependency the ssl flags used for setting up a TLS connection to a server are overwitten with wrong settings. This results in a missing validation of the server certificate and thus in a possible TLS MITM szenario.

Status at the source

Affected products, as the source lists them

VendorProductVersions
SiemensSINUMERIK Analyse MyConditionAll versions: affected
SiemensSINUMERIK Analyze MyPerformanceAll versions: affected
SiemensSINUMERIK Analyze MyPerformance /OEE-MonitorAll versions: affected
SiemensSINUMERIK Analyze MyPerformance /OEE-TuningAll versions: affected
SiemensSINUMERIK Integrate Client 02All versions >= V02.00.12 < 02.00.18: affected
SiemensSINUMERIK Integrate Client 03All versions >= V03.00.12 < 03.00.18: affected
SiemensSINUMERIK Integrate Client 04V04.00.02 and all versions >= V04.00.15 < 04.00.18: affected
SiemensSINUMERIK Integrate for Production 4.1All versions < V4.1 SP10 HF3: affected
SiemensSINUMERIK Integrate for Production 5.1V5.1: affected
SiemensSINUMERIK Manage MyMachinesAll versions: affected
SiemensSINUMERIK Manage MyMachines /RemoteAll versions: affected
SiemensSINUMERIK Manage MyMachines /Spindel MonitorAll versions: affected
SiemensSINUMERIK Manage MyProgramsAll versions: affected
SiemensSINUMERIK Manage MyResources /ProgramsAll versions: affected
SiemensSINUMERIK Manage MyResources /ToolsAll versions: affected
SiemensSINUMERIK Manage MyToolsAll versions: affected
SiemensSINUMERIK Operate V4.8All versions < V4.8 SP8: affected
SiemensSINUMERIK Operate V4.93All versions < V4.93 HF7: affected
SiemensSINUMERIK Operate V4.94All versions < V4.94 HF5: affected
SiemensSINUMERIK Optimize MyProgramming /NX-Cam EditorAll versions: affected
Products named in NVD's CPE match criteria (10)
  • cpe:2.3:o:siemens:sinumerik_analyse_mycondition_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:sinumerik_analyze_myperformance_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:sinumerik_integrate_client_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:sinumerik_integrate_for_production_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:sinumerik_manage_mymachines_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:sinumerik_manage_myprograms_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:sinumerik_manage_myresources_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:sinumerik_manage_mytools_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:sinumerik_operate_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:sinumerik_optimize_myprogramming_firmware:-:*:*:*:*:*:*:*

DeSpy has not checked any unit, hardware revision or firmware. A product missing here is not a statement that it is unaffected.

Scores, as their sources published them

DeSpy does not score records. These are the sources' own values.

Weaknesses

CWE-295

Sources

References the source lists

Source dates: published 2021-07-13, last changed 2026-06-17. DeSpy's copy of this version is dated 2026-09-28.

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.

Scope, sources and licences →