CVE-2024-46888: Path Traversal
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly sanitize user provided paths for SFTP-based file up- and downloads. This could allow an authenticated remote attacker to manipulate arbitrary files on the filesystem and achieve arbitrary code execution on the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46888?
CVE-2024-46888 is classified with a high severity due to its potential for file manipulation by authenticated attackers.
How do I fix CVE-2024-46888?
To fix CVE-2024-46888, update your SINEC INS software to version 1.0 SP2 Update 3 or later.
What versions of SINEC INS are affected by CVE-2024-46888?
All versions of SINEC INS prior to 1.0 SP2 Update 3 are affected by CVE-2024-46888.
What type of attack does CVE-2024-46888 allow?
CVE-2024-46888 allows authenticated remote attackers to manipulate arbitrary files on the filesystem.
Is authentication required to exploit CVE-2024-46888?
Yes, authentication is required for an attacker to exploit CVE-2024-46888.