ICSA-22-298-02
·
Published 2025-09-30
·
View on CISA ICS-CERT ↗
HEIDENHAIN Controller TNC (Update A)
CVSS 8.1
HIGH
Risk Summary
Successful exploitation of this vulnerability could cause a loss of sensitive data, manipulation of information, and a denial-of-service.
CVEs (1)
Remediations
- HEIDENHAIN has identified the following specific workarounds and mitigations users can apply to reduce risk:
- Block LSV2 and DNC communication using the integrated firewall in the controller's operating system.
- Use zone firewalls to isolate and segment the network of the affected devices.
- Ask your machinery vendor (running HEIDENHAIN controllers) for updates to a recent software version, where SSH tunneling is standard.
Affected Vendors
HEIDENHAIN
Affected Products (1)
HEIDENHAIN
·
HEIDENHAIN Controller TNC 640 NC Software
340590_07_SP5
Affected Sectors
Critical Manufacturing, Communications, Energy, Healthcare and Public Health
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more