CVE-2022-45094: Command Injection
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product, could potentially inject commands into the dhcpd configuration of the affected product. An attacker might leverage this to trigger remote code execution on the affected component.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-45094.
What is the severity level of CVE-2022-45094?
The severity level of CVE-2022-45094 is high.
Which software versions are affected by CVE-2022-45094?
All versions of Siemens SINEC INS prior to V1.0 SP2 Update 1 are affected by CVE-2022-45094.
How can an attacker exploit CVE-2022-45094?
An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product can potentially inject commands into the dhcpd configuration.
Are there any fixes available for CVE-2022-45094?
Yes, Siemens has released an update (V1.0 SP2 Update 1) to address CVE-2022-45094. It is recommended to apply the update as soon as possible.