{"document":{"acknowledgments":[{"organization":"CERTVDE","summary":"Coordination","urls":["https://certvde.com/en/"]}],"aggregate_severity":{"namespace":"https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale","text":"Critical"},"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"Com-Server firmware versions prior to 1.60 support the insecure TLS 1.0 and TLS 1.1 protocols, which are susceptible to man-in-the-middle attacks and thereby compromise the confidentiality and integrity of data.","title":"Summary"},{"category":"description","text":"An attacker with network access could exploit the use of insecure TLS 1.0 and TLS 1.1 protocols to intercept and manipulate encrypted communications between the Com-Server and connected systems. This could lead to unauthorized data access, credential theft, compromising the confidentiality and integrity of transmitted information.","title":"Impact"},{"category":"description","text":"Update the Com-Server firmware to version 1.60.","title":"Remediation"}],"publisher":{"category":"vendor","contact_details":"security@wut.de","name":"Wiesemann & Theis GmbH","namespace":"https://www.wut.de"},"references":[{"category":"self","summary":"VDE-2025-031: Wiesemann & Theis: Multiple products from Wiesemann & Theis support deprecated TLS protocol versions - HTML","url":"https://certvde.com/en/advisories/VDE-2025-031/"},{"category":"self","summary":"VDE-2025-031: Wiesemann & Theis: Multiple products from Wiesemann & Theis support deprecated TLS protocol versions - CSAF","url":"https://wut.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-031.json"},{"category":"external","summary":"Wiesemann & Theis advisory overview at CERT@VDE","url":"https://certvde.com/en/advisories/vendor/wut/"},{"category":"external","summary":"IT- and Product Security at W&T","url":"https://www.wut.de/e-wwwww-si-inus-000.php"}],"title":"Wiesemann & Theis: Multiple products from Wiesemann & Theis support deprecated TLS protocol versions","tracking":{"aliases":["VDE-2025-031"],"current_release_date":"2025-04-28T10:00:00.000Z","generator":{"date":"2025-04-25T11:58:50.193Z","engine":{"name":"Secvisogram","version":"2.5.23"}},"id":"VDE-2025-031","initial_release_date":"2025-04-28T10:00:00.000Z","revision_history":[{"date":"2025-04-28T10:00:00.000Z","number":"1","summary":"Initial revision"}],"status":"final","version":"1"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"Com-Server++","product":{"name":"Com-Server++","product_id":"CSAFPID-11001","product_identification_helper":{"model_numbers":["58665"]}}},{"category":"product_name","name":"Com-Server PoE 3x Isolated","product":{"name":"Com-Server PoE 3x Isolated","product_id":"CSAFPID-11002","product_identification_helper":{"model_numbers":["58662"]}}},{"category":"product_name","name":"Com-Server 20mA","product":{"name":"Com-Server 20mA","product_id":"CSAFPID-11003","product_identification_helper":{"model_numbers":["58664"]}}},{"category":"product_name","name":"Com-Server OEM","product":{"name":"Com-Server OEM","product_id":"CSAFPID-11004","product_identification_helper":{"model_numbers":["58461"]}}},{"category":"product_name","name":"Com-Server UL","product":{"name":"Com-Server UL","product_id":"CSAFPID-11005","product_identification_helper":{"model_numbers":["58669"]}}}],"category":"product_family","name":"Hardware"},{"branches":[{"category":"product_version_range","name":"<1.60","product":{"name":"Firmware <1.60","product_id":"CSAFPID-21001"}},{"category":"product_version","name":"1.60","product":{"name":"Firmware 1.60","product_id":"CSAFPID-22001"}}],"category":"product_family","name":"Firmware"}],"category":"vendor","name":"Wiesemann & Theis"}],"product_groups":[{"group_id":"CSAFGID-0001","product_ids":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004","CSAFPID-31005"],"summary":"Affected products."},{"group_id":"CSAFGID-0002","product_ids":["CSAFPID-32001","CSAFPID-32002","CSAFPID-32003","CSAFPID-32004","CSAFPID-32005"],"summary":"Fixed Products."}],"relationships":[{"category":"installed_on","full_product_name":{"name":"Firmware <1.60 installed on Com-Server++","product_id":"CSAFPID-31001"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"Firmware <1.60 installed on Com-Server PoE 3x Isolated","product_id":"CSAFPID-31002"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"Firmware <1.60 installed on Com-Server 20mA","product_id":"CSAFPID-31003"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11003"},{"category":"installed_on","full_product_name":{"name":"Firmware <1.60 installed on Com-Server OEM","product_id":"CSAFPID-31004"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11004"},{"category":"installed_on","full_product_name":{"name":"Firmware <1.60 installed on Com-Server UL","product_id":"CSAFPID-31005"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11005"},{"category":"installed_on","full_product_name":{"name":"Firmware 1.60 installed on Com-Server++","product_id":"CSAFPID-32001"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"Firmware 1.60 installed on Com-Server PoE 3x Isolated","product_id":"CSAFPID-32002"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"Firmware 1.60 installed on Com-Server 20mA","product_id":"CSAFPID-32003"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11003"},{"category":"installed_on","full_product_name":{"name":"Firmware 1.60 installed on Com-Server OEM","product_id":"CSAFPID-32004"},"product_reference":"CSAFPID-11004","relates_to_product_reference":"CSAFPID-11004"},{"category":"installed_on","full_product_name":{"name":"Firmware 1.60 installed on Com-Server UL","product_id":"CSAFPID-32005"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11005"}]},"vulnerabilities":[{"cve":"CVE-2025-3200","cwe":{"id":"CWE-327","name":"Use of a Broken or Risky Cryptographic Algorithm"},"notes":[{"audience":"all","category":"description","text":"An unauthenticated remote attacker could exploit the used, insecure TLS 1.0 and TLS 1.1 protocols to intercept and manipulate encrypted communications between the Com-Server and connected systems.","title":"Vulnerability Description"}],"product_status":{"fixed":["CSAFPID-32001","CSAFPID-32002","CSAFPID-32003","CSAFPID-32004","CSAFPID-32005"],"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004","CSAFPID-31005"]},"remediations":[{"category":"mitigation","details":"Access to the WBM should be limited to trustworthy networks or peers. ","group_ids":["CSAFGID-0001"]},{"category":"vendor_fix","details":"Update the Com-Server firmware to version 1.60.\n","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","environmentalScore":9.1,"environmentalSeverity":"CRITICAL","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":9.1,"temporalSeverity":"CRITICAL","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004","CSAFPID-31005"]}],"title":"CVE-2025-3200"}]}