Siemens SICAM TOOLBOX II
cpe:2.3:a:siemens:sicam_toolbox_ii:*:*:*:*:*:*:*
- < V07.11
A vulnerability exists in Siemens SICAM Toolbox II in all versions prior to 07.11. The issue arises because the application fails to properly validate the extended key usage attribute of TLS certificates from managed devices during HTTPS connections. This flaw could enable an attacker to perform a man-in-the-middle (MitM) attack.
Exploitation of this vulnerability could lead to a man-in-the-middle (MitM) attack, where an attacker could intercept and potentially alter communications between the application and a managed device.
Users are advised to update SICAM Toolbox II to version 07.11 or later. For guidance on applying the update, refer to the Siemens support page for SICAM Toolbox II.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.