CRITICAL🇵🇱 Wersja polska

CVE-2022-45092

CVSS 9.9v3.1pub. 2023-01-10upd. 2024-11-21

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product, could potentially read and write arbitrary files from and to the device's file system. An attacker might leverage this to trigger remote code execution on the affected component.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Siemens Sinec Ins

    APP
    Siemens
    1.0< 1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEPath Traversal
CWE
References

Related vulnerabilities

CVE-2024-46890CRITICAL9.4PL ✓same product

Command injection w Siemens SINEC INS – wykonanie kodu na systemie operacyjnym

CVE-2024-46888CRITICAL9.4PL ✓same product

Path Traversal w SINEC INS umożliwia RCE przez SFTP

CVE-2022-35255CRITICAL9.1PL ✓same product

Słaba losowość w generowaniu kluczy WebCrypto w Node.js 18

CVE-2021-22945CRITICAL9.1PL ✓same product

Double-free w libcurl przy wysyłaniu danych do serwera MQTT

CVE-2023-44487HIGH7.5⚠ KEVsame product

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can ...