CVE-2023-48429: Low severity Siemens Sinec Ins vulnerability
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The Web UI of affected devices does not check the length of parameters in certain conditions. This allows a malicious admin to crash the server by sending a crafted request to the server. The server will automatically restart.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48429?
CVE-2023-48429 is considered a high severity vulnerability due to its ability to allow a malicious admin to crash the server.
How do I fix CVE-2023-48429?
To fix CVE-2023-48429, upgrade to SINEC INS version 1.0 SP2 Update 2 or later.
What are the affected versions in CVE-2023-48429?
CVE-2023-48429 affects all versions of SINEC INS below version 1.0 SP2 Update 2.
What type of attack can CVE-2023-48429 facilitate?
CVE-2023-48429 can facilitate a denial-of-service attack by crashing the server through crafted requests.
Who is affected by CVE-2023-48429?
Organizations using affected versions of SINEC INS, particularly those with administrative access, are vulnerable to CVE-2023-48429.