CVE-2022-41648 - CVE House
Back to Database
Status published Critical CVE-2022-41648

The HEIDENHAIN Controller TNC 640 NC software Version 340590 07...

Vulnerability Description

The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC communication for CNC machines. Authentication is not enabled by default for DNC communication. This vulnerability may allow an attacker to deny service on the production line, steal sensitive data from the production line, and alter any products created by the production line. Note: CNC machines running the TNC 640 controller require DNC to be enabled for DNC communication to be present.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-41648

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Marco Balduzzi

Affected Vendor

Affected Software

HEIDENHAIN Controller TNC 640 NC Software
Vulnerable Versions:
340590 07 SP5

Timeline

Official Publish: October 28th, 2022
Last Modified: October 13th, 2025
Added to House: July 21st, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.