CVE-2017-2685: Infoleak
Siemens SINUMERIK Integrate Operate Clients between 2.0.3.00.016 (including) and 2.0.6 (excluding) and between 3.0.4.00.032 (including) and 3.0.6 (excluding) contain a vulnerability that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2685?
CVE-2017-2685 has a critical severity rating due to its potential to allow unauthorized data access during TLS sessions.
How do I fix CVE-2017-2685?
To fix CVE-2017-2685, update the Siemens SINUMERIK Integrate Operate Clients to a version after 2.0.6 and 3.0.6.
What systems are affected by CVE-2017-2685?
CVE-2017-2685 affects Siemens SINUMERIK Integrate Operate Clients versions 2.0.3.00.016 to 2.0.6 and 3.0.4.00.032 to 3.0.6.
What kind of attack can CVE-2017-2685 be exploited by?
CVE-2017-2685 can be exploited by a man-in-the-middle (MITM) attack.
Is there a workaround for CVE-2017-2685 if I cannot update?
Currently, there is no official workaround for CVE-2017-2685 recommended by Siemens, so updating is essential.