Denial of Service and Command Execution in SINEC INS by Siemens
CVE-2023-48428
7.2HIGH
What is CVE-2023-48428?
A security flaw has been discovered in SINEC INS, where the radius configuration mechanism inadequately verifies uploaded certificates. This oversight enables a malicious administrator to upload a specially crafted certificate, which may lead to a denial-of-service condition or potentially execute unauthorized commands at the system level. Such a vulnerability poses serious risks to the operational integrity and security of affected systems.
Affected Version(s)
SINEC INS All versions < V1.0 SP2 Update 2