CVE-2022-45093: Path Traversal
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product as well as with access to the SFTP server of the affected product (22/tcp), could potentially read and write arbitrary files from and to the device's file system. An attacker might leverage this to trigger remote code execution on the affected component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-45093?
The severity of CVE-2022-45093 is high (8.8).
What is the affected software for CVE-2022-45093?
The affected software for CVE-2022-45093 is Siemens Sinec Ins (all versions < V1.0 SP2 Update 1).
What can an authenticated remote attacker do with CVE-2022-45093?
An authenticated remote attacker with access to the Web Based Management (443/tcp) and the SFTP server (22/tcp) of the affected product can potentially read and write data.
How can I fix CVE-2022-45093?
To fix CVE-2022-45093, upgrade to version V1.0 SP2 Update 1 or a later version of Siemens Sinec Ins.
What is the Common Weakness Enumeration (CWE) for CVE-2022-45093?
The Common Weakness Enumeration (CWE) for CVE-2022-45093 is CWE-22.