CVE-2023-48430
published 2023-12-12CVE-2023-48430: A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The REST API of affected devices does not check the length of parameters…
PriorityP411low2.7CVSS 3.1
AVNACLPRHUINSUCNINAL
EPSS
0.58%
44.5th percentile
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The REST API of affected devices does not check the length of parameters in certain conditions. This allows a malicious admin to crash the server by sending a crafted request to the API. The server will automatically restart.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | sinec_ins | < 1.0 | 1.0 |
| siemens | sinec_ins | — | — |
| siemens | sinec_ins | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r7vh-7qjc-wcjc: A vulnerability has been identified in SINEC INS (All versions < V1
ghsa_unreviewed·2023-12-12
CVE-2023-48430 [LOW] CWE-392 GHSA-r7vh-7qjc-wcjc: A vulnerability has been identified in SINEC INS (All versions < V1
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The REST API of affected devices does not check the length of parameters in certain conditions. This allows a malicious admin to crash the server by sending a crafted request to the API. The server will automatically restart.
CISA ICS
Siemens SINEC INS
cisa_ics·2023-12-14·CVSS 7.5
[HIGH] Siemens SINEC INS
ICS Advisory
##
Siemens SINEC INS
Release DateDecember 14, 2023
Alert CodeICSA-23-348-16
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.1
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerabilities: Improper Certificate Validation, Improper Input Validation, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Unexpected Status Code or Return Value, Missing
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-12-12
Published