Lucene search

K
cveIcscertCVE-2022-41648
HistoryOct 28, 2022 - 6:15 p.m.

CVE-2022-41648

2022-10-2818:15:12
CWE-287
icscert
web.nvd.nist.gov
34
2
heidenhain
controller
tnc 640
heros
hartford
cnc
vulnerability
authentication
denial of service
data theft
product alteration
nvd
cve-2022-41648

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.002

Percentile

57.0%

The HEIDENHAIN Controller TNC 640, version 340590 07 SP5, running HEROS 5.08.3 controlling the HARTFORD 5A-65E CNC machine is vulnerable to improper authentication, which may allow an attacker to deny service to the production line, steal sensitive data from the production line, and alter any products created by the production line.

Affected configurations

Nvd
Node
heidenhaintnc_640Match-
AND
heidenhaintnc_640_programming_stationMatch340590_07sp5
OR
heidenhainherosMatch5.08.3
VendorProductVersionCPE
heidenhaintnc_640-cpe:2.3:h:heidenhain:tnc_640:-:*:*:*:*:*:*:*
heidenhaintnc_640_programming_station340590_07cpe:2.3:a:heidenhain:tnc_640_programming_station:340590_07:sp5:*:*:*:*:*:*
heidenhainheros5.08.3cpe:2.3:o:heidenhain:heros:5.08.3:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "HEIDENHAIN",
    "product": "Controller TNC 640",
    "versions": [
      {
        "version": "Version 340590 07 SP5, running HEROS 5.08.3 controlling the HARTFORD 5A-65E CNC machine",
        "status": "affected"
      }
    ]
  }
]

Social References

More

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.002

Percentile

57.0%

Related for CVE-2022-41648