📦 Sinec Ins

by Siemens

🔍 What is Sinec Ins?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-46890

CRITICAL CVSS 9.1 Nov 12, 2024

This vulnerability allows authenticated remote attackers with high privileges in SINEC INS to execute arbitrary operating system commands through improper input validation in the web API. All versions...

CVE-2023-48428

HIGH CVSS 7.2 Dec 12, 2023

This vulnerability in SINEC INS allows malicious administrators to upload specially crafted certificates through the RADIUS configuration mechanism, bypassing validation checks. Successful exploitatio...

CVE-2022-32212

HIGH CVSS 8.1 Jul 14, 2022

This CVE describes an OS command injection vulnerability in Node.js that allows attackers to bypass host validation checks and perform DNS rebinding attacks. It affects Node.js applications that make ...

CVE-2021-25217

HIGH CVSS 7.4 May 26, 2021

A memory corruption vulnerability in ISC DHCP allows attackers to cause denial of service by crashing dhclient or dhcpd processes when they parse malicious lease files. The vulnerability affects DHCP ...

CVE-2021-23337

HIGH CVSS 7.2 Feb 15, 2021

Lodash versions before 4.17.21 contain a command injection vulnerability in the template function that allows attackers to execute arbitrary commands on the host system. This affects any application u...

CVE-2024-46889

MEDIUM CVSS 5.3 Nov 12, 2024

SINEC INS versions before V1.0 SP2 Update 3 use hard-coded cryptographic keys to obfuscate configuration files, allowing attackers to reverse-engineer the application binary to obtain these keys and d...

CVE-2024-46892

MEDIUM CVSS 4.9 Nov 12, 2024

This vulnerability allows authenticated attackers to maintain active sessions even after their user accounts have been disabled or deleted in SINEC INS. Attackers could continue performing malicious a...