A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate input sent to specific endpoints of its web API. This could allow an authenticated remote attacker with high privileges on the application to execute arbitrary code on the underlying OS.
The application does not perform proper validation of input data sent to specific endpoints of its web API. An authenticated remote attacker with high privileges in the application can submit crafted input data containing malicious system commands. Due to lack of appropriate filtering, this data is interpreted and executed directly by the operating system (CWE-78: Improper Neutralization of Special Elements used in an OS Command).
An attacker can execute arbitrary code on the operating system on which the application runs, leading to complete takeover of the server and potential breach of confidentiality, integrity, and availability of both the system and its connected network resources.
Update Siemens SINEC INS to version V1.0 SP2 Update 3 or later. Detailed information regarding the update is available in the vendor's advisory: https://cert-portal.siemens.com/productcert/html/ssa-915275.html
Siemens SINEC INS – all versions earlier than V1.0 SP2 Update 3.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSiemens Sinec Ins
APPSiemens1.0< 1.0
Related vulnerabilities
Path Traversal w SINEC INS umożliwia RCE przez SFTP
Path Traversal w Siemens SINEC INS umożliwiający RCE
Słaba losowość w generowaniu kluczy WebCrypto w Node.js 18
Double-free w libcurl przy wysyłaniu danych do serwera MQTT
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can ...