Vulnerability in SINEC INS Software by Siemens
CVE-2023-48431
6.8MEDIUM
What is CVE-2023-48431?
A vulnerability exists in SINEC INS software where it fails to properly validate responses from a UMC server. An attacker can exploit this flaw by setting up a malicious UMC server or manipulating the traffic from a legitimate server, potentially leading to system crashes and other disruptions. Immediate updates to version V1.0 SP2 Update 2 or later are recommended to mitigate this issue.
Affected Version(s)
SINEC INS All versions < V1.0 SP2 Update 2