Parameter Length Validation Issue in SINEC INS by Siemens
CVE-2023-48430

2.7LOW

Key Information:

Vendor
Siemens
Status
Vendor
CVE Published:
12 December 2023

Summary

A vulnerability has been identified in SINEC INS, where the REST API does not sufficiently validate the length of parameters under certain conditions. This oversight enables a malicious administrator to exploit the flaw by sending specifically crafted requests to the API. As a result, the server may crash and automatically restart, potentially leading to service interruptions and exposing the system to further attacks.

Affected Version(s)

SINEC INS All versions < V1.0 SP2 Update 2

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.