Parameter Length Validation Issue in SINEC INS by Siemens
CVE-2023-48430
2.7LOW
What is CVE-2023-48430?
A vulnerability has been identified in SINEC INS, where the REST API does not sufficiently validate the length of parameters under certain conditions. This oversight enables a malicious administrator to exploit the flaw by sending specifically crafted requests to the API. As a result, the server may crash and automatically restart, potentially leading to service interruptions and exposing the system to further attacks.
Affected Version(s)
SINEC INS All versions < V1.0 SP2 Update 2