CVE-2024-46894: Infoleak
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate authorization of a user to query the "/api/sftp/users" endpoint. This could allow an authenticated remote attacker to gain knowledge about the list of configured users of the SFTP service and also modify that configuration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46894?
CVE-2024-46894 has been rated as a critical vulnerability due to its potential impact on system security.
How do I fix CVE-2024-46894?
To fix CVE-2024-46894, upgrade SINEC INS to version V1.0 SP2 Update 3 or later.
What specific issue does CVE-2024-46894 address?
CVE-2024-46894 addresses inadequate authorization validation for the "/api/sftp/users" endpoint.
Who is affected by CVE-2024-46894?
Any user of SINEC INS versions prior to V1.0 SP2 Update 3 is vulnerable to CVE-2024-46894.
Can CVE-2024-46894 lead to data exposure?
Yes, CVE-2024-46894 may allow an authenticated attacker to gain unauthorized access to user information.