A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly sanitize user provided paths for SFTP-based file up- and downloads. This could allow an authenticated remote attacker to manipulate arbitrary files on the filesystem and achieve arbitrary code execution on the device.
2024-11-12T13:15:08.927
2024-11-13T23:11:24.570
Analyzed
CVSSv3.1: 9.9 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | siemens | sinec_ins | < 1.0 | Yes |
Application | siemens | sinec_ins | 1.0 | Yes |
Application | siemens | sinec_ins | 1.0 | Yes |
Application | siemens | sinec_ins | 1.0 | Yes |
Application | siemens | sinec_ins | 1.0 | Yes |
Application | siemens | sinec_ins | 1.0 | Yes |