CVE-2022-41648
The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC communication for CNC machines. Authentication is not enabled by default for DNC communication. This vulnerability may allow an attacker to deny service on the production line, steal sensitive data from the production line, and alter any products created by the production line. Note: CNC machines running the TNC 640 controller require DNC to be enabled for DNC communication to be present.
Published:Oct 28, 2022
Last Modified:Oct 13, 2025
EPS:Oct 28, 2022
EPSS Score:0.00068
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Heidenhain
Product
Heros
Heidenhain
Heros
Vendor
Heidenhain
Product
Tnc 640
Heidenhain
Tnc 640
Vendor
Heidenhain
Product
Tnc 640 Programming Station
Heidenhain
Tnc 640 Programming Station
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
