First published: Tue Oct 11 2022(Updated: )
A vulnerability has been identified in Industrial Edge Management (All versions < V1.5.1). The affected software does not properly validate the server certificate when initiating a TLS connection. This could allow an attacker to spoof a trusted entity by interfering in the communication path between the client and the intended server.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Industrial Edge Management Hub | <1.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40147 is a vulnerability identified in Siemens Industrial Edge Management software versions prior to 1.5.1.
CVE-2022-40147 has a severity rating of 7.4 (High).
CVE-2022-40147 allows an attacker to spoof a trusted entity by interfering in the communication path between the software and the server due to improper validation of the server certificate.
To fix CVE-2022-40147, users should update their Siemens Industrial Edge Management software to version 1.5.1 or newer.
More information about CVE-2022-40147 can be found in the Siemens ProductCERT advisory: https://cert-portal.siemens.com/productcert/pdf/ssa-649853.pdf