CVE-2023-48431: High severity siemens sinec ins vulnerability
Published Dec 12, 2023
·Updated
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected software does not correctly validate the response received by an UMC server. An attacker can use this to crash the affected software by providing and configuring a malicious UMC server or by manipulating the traffic from a legitimate UMC server (i.e. leveraging CVE-2023-48427).
Affected Software
5 affected components
Siemens Sinec Ins<1.0
Siemens Sinec Ins=1.0
Siemens Sinec Ins=1.0-sp1
Siemens Sinec Ins=1.0-sp2
Siemens Sinec Ins=1.0-sp2_update_1
Remediation
Event History
Dec 12, 2023
CVE Published
11:27 AM
Data Sourced
11:27 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-48431?
The severity of CVE-2023-48431 is high with a score of 8.6.
2
How can the vulnerability CVE-2023-48431 be exploited?
An attacker can exploit CVE-2023-48431 by crashing the affected software using a malicious UMC server or by manipulating the response received by the UMC server.
3
Is Siemens SINEC INS affected by CVE-2023-48431?
Siemens SINEC INS versions up to V1.0 SP2 Update 2 are affected by CVE-2023-48431.