CVE-2023-48429

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The Web UI of affected devices does not check the length of parameters in certain conditions. This allows a malicious admin to crash the server by sending a crafted request to the server. The server will automatically restart.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:sinec_ins:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinec_ins:1.0:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sinec_ins:1.0:sp1:*:*:*:*:*:*
cpe:2.3:a:siemens:sinec_ins:1.0:sp2:*:*:*:*:*:*
cpe:2.3:a:siemens:sinec_ins:1.0:sp2_update_1:*:*:*:*:*:*

History

14 Dec 2023, 19:37

Type Values Removed Values Added
CPE cpe:2.3:a:siemens:sinec_ins:1.0:sp2:*:*:*:*:*:*
cpe:2.3:a:siemens:sinec_ins:1.0:sp1:*:*:*:*:*:*
cpe:2.3:a:siemens:sinec_ins:1.0:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sinec_ins:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinec_ins:1.0:sp2_update_1:*:*:*:*:*:*
References () https://cert-portal.siemens.com/productcert/pdf/ssa-077170.pdf - () https://cert-portal.siemens.com/productcert/pdf/ssa-077170.pdf - Patch, Vendor Advisory
CWE CWE-394 CWE-754

12 Dec 2023, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-12 12:15

Updated : 2024-02-05 00:22


NVD link : CVE-2023-48429

Mitre link : CVE-2023-48429

CVE.ORG link : CVE-2023-48429


JSON object : View

Products Affected

siemens

  • sinec_ins
CWE
CWE-754

Improper Check for Unusual or Exceptional Conditions

CWE-394

Unexpected Status Code or Return Value