CVE-2017-6873

A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack on the integrated web server on port 443/tcp.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:siemens:ozw772_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:ozw772:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:ozw672_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:ozw672:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:30

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/99473 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/99473 - Third Party Advisory, VDB Entry
References () https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-563539.pdf - Vendor Advisory () https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-563539.pdf - Vendor Advisory

Information

Published : 2017-08-08 00:29

Updated : 2024-11-21 03:30


NVD link : CVE-2017-6873

Mitre link : CVE-2017-6873

CVE.ORG link : CVE-2017-6873


JSON object : View

Products Affected

siemens

  • ozw672
  • ozw772_firmware
  • ozw672_firmware
  • ozw772
CWE
CWE-306

Missing Authentication for Critical Function

NVD-CWE-noinfo