Parameter Length Validation Issue in SINEC INS by Siemens
CVE-2023-48430
2.7LOW
Summary
A vulnerability has been identified in SINEC INS, where the REST API does not sufficiently validate the length of parameters under certain conditions. This oversight enables a malicious administrator to exploit the flaw by sending specifically crafted requests to the API. As a result, the server may crash and automatically restart, potentially leading to service interruptions and exposing the system to further attacks.
Affected Version(s)
SINEC INS All versions < V1.0 SP2 Update 2
References
CVSS V3.1
Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved