← Back to home
ICSA-22-298-02  ·  Published 2025-09-30  ·  View on CISA ICS-CERT ↗

HEIDENHAIN Controller TNC (Update A)

CVSS 8.1 HIGH

Risk Summary

Successful exploitation of this vulnerability could cause a loss of sensitive data, manipulation of information, and a denial-of-service.

CVEs (1)

Remediations

  • HEIDENHAIN has identified the following specific workarounds and mitigations users can apply to reduce risk:
  • Block LSV2 and DNC communication using the integrated firewall in the controller's operating system.
  • Use zone firewalls to isolate and segment the network of the affected devices.
  • Ask your machinery vendor (running HEIDENHAIN controllers) for updates to a recent software version, where SSH tunneling is standard.

Affected Vendors

HEIDENHAIN

Affected Products (1)

HEIDENHAIN · HEIDENHAIN Controller TNC 640 NC Software 340590_07_SP5

Affected Sectors

Critical Manufacturing, Communications, Energy, Healthcare and Public Health

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more