A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product, could potentially read and write arbitrary files from and to the device's file system. An attacker might leverage this to trigger remote code execution on the affected component.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HSiemens Sinec Ins
APPSiemens1.0< 1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEPath Traversal
CWE
Related vulnerabilities
CVE-2024-46890CRITICAL9.4PL ✓same product
Command injection w Siemens SINEC INS – wykonanie kodu na systemie operacyjnym
CVE-2024-46888CRITICAL9.4PL ✓same product
Path Traversal w SINEC INS umożliwia RCE przez SFTP
CVE-2022-35255CRITICAL9.1PL ✓same product
Słaba losowość w generowaniu kluczy WebCrypto w Node.js 18
CVE-2021-22945CRITICAL9.1PL ✓same product
Double-free w libcurl przy wysyłaniu danych do serwera MQTT
CVE-2023-44487HIGH7.5⚠ KEVsame product
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can ...