Vulnerability Details CVE-2024-31854
A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a managed device, the affected application doesn't check device's certificate common name against an expected value.
This could allow an attacker to execute an on-path network (MitM) attack.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 6.9%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2024-31854
-
cpe:2.3:a:siemens:sicam_toolbox_ii:-
-
cpe:2.3:a:siemens:sicam_toolbox_ii:07.00
-
cpe:2.3:a:siemens:sicam_toolbox_ii:07.01