The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC communication for CNC machines. Authentication is not enabled by default for DNC communication. This vulnerability may allow an attacker to deny service on the production line, steal sensitive data from the production line, and alter any products created by the production line. Note: CNC machines running the TNC 640 controller require DNC to be enabled for DNC communication to be present.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-44836 The HEIDENHAIN Controller TNC 640, version 340590 07 SP5, running HEROS 5.08.3 controlling the HARTFORD 5A-65E CNC machine is vulnerable to improper authentication, which may allow an attacker to deny service to the production line, steal sensitive data from the production line, and alter any products created by the production line.
Fixes

Solution

HEIDENHAIN has identified the following specific workarounds and mitigations users can apply to reduce risk: * Block LSV2 and DNC communication using the integrated firewall in the controller's operating system. * Use zone firewalls to isolate and segment the network of the affected devices. * Ask your machinery vendor (running HEIDENHAIN controllers) for updates to a recent software version, where SSH tunneling is standard.


Workaround

HEIDENHAIN has identified the following specific workarounds and mitigations users can apply to reduce risk: * Block LSV2 and DNC communication using the integrated firewall in the controller's operating system. * Use zone firewalls to isolate and segment the network of the affected devices. * Ask machinery vendor (running HEIDENHAIN controllers) for updates to a recent software version, where SSH tunneling is standard.

History

Mon, 13 Oct 2025 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Mon, 13 Oct 2025 12:30:00 +0000

Type Values Removed Values Added
Description The HEIDENHAIN Controller TNC 640, version 340590 07 SP5, running HEROS 5.08.3 controlling the HARTFORD 5A-65E CNC machine is vulnerable to improper authentication, which may allow an attacker to deny service to the production line, steal sensitive data from the production line, and alter any products created by the production line. The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC communication for CNC machines. Authentication is not enabled by default for DNC communication. This vulnerability may allow an attacker to deny service on the production line, steal sensitive data from the production line, and alter any products created by the production line. Note: CNC machines running the TNC 640 controller require DNC to be enabled for DNC communication to be present.
Weaknesses CWE-1188
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Wed, 16 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-10-13T12:09:37.939Z

Reserved: 2022-09-29T00:00:00.000Z

Link: CVE-2022-41648

cve-icon Vulnrichment

Updated: 2024-08-03T12:49:43.602Z

cve-icon NVD

Status : Modified

Published: 2022-10-28T18:15:12.723

Modified: 2025-10-13T13:15:31.543

Link: CVE-2022-41648

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.