Arbitrary File Manipulation and Code Execution Vulnerability
CVE-2024-46888
9.9CRITICAL
What is CVE-2024-46888?
A vulnerability exists in the SINEC INS application that affects versions prior to V1.0 SP2 Update 3, which fails to properly sanitize user-provided path inputs during SFTP file uploads and downloads. This flaw enables authenticated remote attackers to manipulate arbitrary files on the system, potentially leading to unauthorized code execution. Organizations utilizing SINEC INS should evaluate their current version and apply necessary security updates to mitigate this significant risk.
Affected Version(s)
SINEC INS 0