← volver
CVE-2024-46888

CVE-2024-46888

CVSS 9.4 CRITICALEPSS 0.9%CWE-22
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly sanitize user provided paths for SFTP-based file up- and downloads. This could allow an authenticated remote attacker to manipulate arbitrary files on the filesystem and achieve arbitrary code execution on the device.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Productos afectados
Siemens · SINEC INS

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →