A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly sanitize user provided paths for SFTP-based file up- and downloads. This could allow an authenticated remote attacker to manipulate arbitrary files on the filesystem and achieve arbitrary code execution on the device.
The SINEC INS application does not properly sanitize file paths supplied by users during file upload and download operations performed via the SFTP protocol. An attacker with access to a user account can craft a malicious path containing path traversal sequences (e.g., '../') to escape the allowed directory and gain access to arbitrary locations on the file system. Successful exploitation of this vulnerability allows overwriting or reading critical system files, which consequently enables arbitrary code execution on the device (RCE).
An attacker can manipulate arbitrary files on the device's file system and achieve full remote code execution (RCE), which may lead to complete takeover of the device and potentially related systems.
Siemens SINEC INS should be updated to version V1.0 SP2 Update 3 or later. Detailed information and patches are available in the Siemens security bulletin: https://cert-portal.siemens.com/productcert/html/ssa-915275.html
Siemens SINEC INS — all versions below V1.0 SP2 Update 3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSiemens Sinec Ins
APPSiemens1.0< 1.0
Related vulnerabilities
Command injection w Siemens SINEC INS – wykonanie kodu na systemie operacyjnym
Path Traversal w Siemens SINEC INS umożliwiający RCE
Słaba losowość w generowaniu kluczy WebCrypto w Node.js 18
Double-free w libcurl przy wysyłaniu danych do serwera MQTT
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can ...