Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-40147


A vulnerability has been identified in Industrial Edge Management (All versions < V1.5.1). The affected software does not properly validate the server certificate when initiating a TLS connection. This could allow an attacker to spoof a trusted entity by interfering in the communication path between the client and the intended server.


Published

2022-10-11T11:15:10.417

Last Modified

2024-11-21T07:20:58.717

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.4 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-295
  • Type: Primary
    CWE-295

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application siemens industrial_edge_management < 1.5.1 Yes

References