This page lists publicly disclosed CVE vulnerabilities affecting siemens sicam_toolbox_ii (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2024-31854 | A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a managed device, the affected application doesn't check device's certificate common name against an expected value. This could allow an attacker to execute an on-path network (MitM) attack. | [email protected] | 7.7 | 0.17% | 2025-07-08 | 2026-06-17 |
| CVE-2024-31853 | A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a managed device, the affected application doesn't check the extended key usage attribute of that device's certificate. This could allow an attacker to execute an on-path network (MitM) attack. | [email protected] | 7.7 | 0.17% | 2025-07-08 | 2026-06-17 |
| CVE-2023-38641 | A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.10). The affected application's database service is executed as `NT AUTHORITY\SYSTEM`. This could allow a local attacker to execute operating system commands with elevated privileges. | [email protected] | 7.8 | 0.18% | 2023-08-08 | 2026-06-17 |
| CVE-2022-39062 | A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.10). Affected applications do not properly set permissions for product folders. This could allow an authenticated attacker with low privileges to replace DLLs and conduct a privilege escalation. | [email protected] | 7.8 | 0.15% | 2023-08-08 | 2026-06-17 |
| CVE-2021-45106 | A vulnerability has been identified in SICAM TOOLBOX II (All versions). Affected applications use a circumventable access control within a database service. This could allow an attacker to access the database. | [email protected] | 6.5 | 0.66% | 2022-02-09 | 2026-06-17 |