cbcvebase.

Siemens Sinec Ins vulnerabilities

42 known vulnerabilities affecting siemens/sinec_ins.

Total CVEs
42
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH17MEDIUM16LOW3

Vulnerabilities

Page 1 of 3
CVE-2023-44487P1HIGHCVSS 7.5KEVPoCfixed in 1.0v1.02023-10-10
CVE-2023-44487 [HIGH] CWE-400 CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
nvd
CVE-2021-23337P2HIGHCVSS 7.2PoCfixed in 1.0v1.02021-02-15
CVE-2021-23337 [HIGH] CWE-94 CVE-2021-23337: Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
nvd
CVE-2022-45092P2HIGHCVSS 8.8fixed in 1.0v1.0+1 more2023-01-10
CVE-2022-45092 [HIGH] CWE-22 CVE-2022-45092: A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticate A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product, could potentially read and write arbitrary files from and to the device's file system. An attacker might leverage this to trigger remote code execution on the af
nvd
CVE-2022-2068P2HIGHCVSS 7.3fixed in 1.0v1.02022-06-21
CVE-2022-2068 [HIGH] CVE-2022-2068: In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstanc In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certifica
nvd
CVE-2024-46888P2CRITICALCVSS 9.9fixed in 1.0v1.0+1 more2024-11-12
CVE-2024-46888 [CRITICAL] CWE-22 CVE-2024-46888: A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected ap A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly sanitize user provided paths for SFTP-based file up- and downloads. This could allow an authenticated remote attacker to manipulate arbitrary files on the filesystem and achieve arbitrary code execution on the device.
nvd
CVE-2026-46746P2HIGHCVSS 8.8≤ 1.0v1.0-sp1+7 more2026-06-09
CVE-2026-46746 [HIGH] CWE-78 CVE-2026-46746: A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly sanitize user input in the /api/sftp/uploadFiles endpoint, allowing the injection of shell command payloads via crafted directory names. These payloads are stored and executed when directory listings are retrieved. This could allow an
nvd
CVE-2022-32215P3MEDIUMCVSS 6.5v1.02022-07-14
CVE-2022-32215 [MEDIUM] CWE-444 CVE-2022-32215: The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).
nvd
CVE-2023-48427P2CRITICALCVSS 9.8fixed in 1.0v1.0+1 more2023-12-12
CVE-2023-48427 [CRITICAL] CWE-295 CVE-2023-48427: A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected produc A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the UMC server as well as to manipulate responses, potentially allowing an attacker to escalate privileg
nvd
CVE-2022-45094P2HIGHCVSS 8.8fixed in 1.0v1.0+1 more2023-01-10
CVE-2022-45094 [HIGH] CWE-77 CVE-2022-45094: A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticate A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product, could potentially inject commands into the dhcpd configuration of the affected product. An attacker might leverage this to trigger remote code execution on the a
nvd
CVE-2022-45093P2HIGHCVSS 8.8fixed in 1.0v1.0+1 more2023-01-10
CVE-2022-45093 [HIGH] CWE-22 CVE-2022-45093: A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticate A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product as well as with access to the SFTP server of the affected product (22/tcp), could potentially read and write arbitrary files from and to the device's file system.
nvd
CVE-2026-46749P3CRITICALCVSS 9.8≤ 1.0v1.0-sp1+7 more2026-06-09
CVE-2026-46749 [CRITICAL] CWE-760 CVE-2026-46749: A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected ap A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords
nvd
CVE-2024-46890P3CRITICALCVSS 9.1fixed in 1.0v1.0+1 more2024-11-12
CVE-2024-46890 [CRITICAL] CWE-78 CVE-2024-46890: A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected ap A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate input sent to specific endpoints of its web API. This could allow an authenticated remote attacker with high privileges on the application to execute arbitrary code on the underlying OS.
nvd
CVE-2021-22945P3CRITICALCVSS 9.1fixed in 1.0.1.12021-09-23
CVE-2021-22945 [CRITICAL] CWE-415 CVE-2021-22945: When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances errone When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.
nvd
CVE-2022-32212P3HIGHCVSS 8.1fixed in 1.0v1.02022-07-14
CVE-2022-32212 [HIGH] CWE-284 CVE-2022-32212: A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to a A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.
nvd
CVE-2022-32213P3MEDIUMCVSS 6.5v1.02022-07-14
CVE-2022-32213 [MEDIUM] CWE-444 CVE-2022-32213: The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).
nvd
CVE-2022-35255P3CRITICALCVSS 9.1fixed in 1.0v1.02022-12-05
CVE-2022-35255 [CRITICAL] CWE-338 CVE-2022-35255: A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with Entrop A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data
nvd
CVE-2026-46748P3HIGHCVSS 7.8≤ 1.0v1.0-sp1+7 more2026-06-09
CVE-2026-46748 [HIGH] CWE-250 CVE-2026-46748: A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected sy A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a binary that is configured with the cap_dac_override capability. This capability allows the process to bypass file system permission checks, resulting in unrestricted file system access. This could allow a local attacker to escalate privi
nvd
CVE-2023-48431P3HIGHCVSS 8.6fixed in 1.0v1.02023-12-12
CVE-2023-48431 [HIGH] CVE-2023-48431: A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected softwa A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected software does not correctly validate the response received by an UMC server. An attacker can use this to crash the affected software by providing and configuring a malicious UMC server or by manipulating the traffic from a legitimate UMC server (i.e. leveraging CVE-2
nvd
CVE-2024-46892P3HIGHCVSS 8.1fixed in 1.0v1.0+1 more2024-11-12
CVE-2024-46892 [HIGH] CWE-613 CVE-2024-46892: A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected ap A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly invalidate sessions when the associated user is deleted or disabled or their permissions are modified. This could allow an authenticated attacker to continue performing malicious actions even after their user account has been
nvd
CVE-2021-3749P3HIGHCVSS 7.5fixed in 1.0v1.02021-08-31
CVE-2021-3749 [HIGH] CWE-1333 CVE-2021-3749: axios is vulnerable to Inefficient Regular Expression Complexity axios is vulnerable to Inefficient Regular Expression Complexity
nvd