CRITICAL🇵🇱 Wersja polska

CVE-2024-46890

CVSS 9.4v4.0pub. 2024-11-12upd. 2024-11-13

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate input sent to specific endpoints of its web API. This could allow an authenticated remote attacker with high privileges on the application to execute arbitrary code on the underlying OS.

🤖 AI Analysis
How it works

The application does not perform proper validation of input data sent to specific endpoints of its web API. An authenticated remote attacker with high privileges in the application can submit crafted input data containing malicious system commands. Due to lack of appropriate filtering, this data is interpreted and executed directly by the operating system (CWE-78: Improper Neutralization of Special Elements used in an OS Command).

Impact

An attacker can execute arbitrary code on the operating system on which the application runs, leading to complete takeover of the server and potential breach of confidentiality, integrity, and availability of both the system and its connected network resources.

Mitigation & patch

Update Siemens SINEC INS to version V1.0 SP2 Update 3 or later. Detailed information regarding the update is available in the vendor's advisory: https://cert-portal.siemens.com/productcert/html/ssa-915275.html

Who is affected

Siemens SINEC INS – all versions earlier than V1.0 SP2 Update 3.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Siemens Sinec Ins

    APP
    Siemens
    1.0< 1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCECommand Injection
CWE
References

Related vulnerabilities

CVE-2024-46888CRITICAL9.4PL ✓same product

Path Traversal w SINEC INS umożliwia RCE przez SFTP

CVE-2022-45092CRITICAL9.9PL ✓same product

Path Traversal w Siemens SINEC INS umożliwiający RCE

CVE-2022-35255CRITICAL9.1PL ✓same product

Słaba losowość w generowaniu kluczy WebCrypto w Node.js 18

CVE-2021-22945CRITICAL9.1PL ✓same product

Double-free w libcurl przy wysyłaniu danych do serwera MQTT

CVE-2023-44487HIGH7.5⚠ KEVsame product

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can ...