High severity7.4NVD Advisory· Published Mar 1, 2017· Updated May 13, 2026
CVE-2017-2685
CVE-2017-2685
Description
Siemens SINUMERIK Integrate Operate Clients between 2.0.3.00.016 (including) and 2.0.6 (excluding) and between 3.0.4.00.032 (including) and 3.0.6 (excluding) contain a vulnerability that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack.
Affected products
5- cpe:2.3:a:siemens:sinumerik_integrate_access_mymachine\/ethernet:-:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinumerik_integrate_operate_client:2.0.3.00.016:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:siemens:sinumerik_integrate_operate_client:2.0.3.00.016:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:sinumerik_integrate_operate_client:3.0.4.00.032:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinumerik_operate:4.5:sp6:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:siemens:sinumerik_operate:4.5:sp6:*:*:*:*:*:*
- cpe:2.3:a:siemens:sinumerik_operate:4.7:sp2:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/bid/96519nvdThird Party AdvisoryVDB Entry
- www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-934525.pdfnvdVendor Advisory
News mentions
0No linked articles in our index yet.