Skip to main content

Vendor/product archive

siemens / sinec_ins CVEs

Beta · best-effort

41 CVEs tagged to siemens / sinec_ins5 Critical, 13 High, 20 Medium, 3 Low, 0 Unrated.

CVE-2026-46749

Published Jun 9, 2026

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt…

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-46748

Published Jun 9, 2026

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a binary that is configured with the cap_dac_override capability.…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-46747

Published Jun 9, 2026

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not properly sanitize path input in the `GET /api/sftp/uploadFil…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-46746

Published Jun 9, 2026

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly sanitize user input in the /api/sftp/uploadFiles endpoint, a…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-46894

Published Nov 12, 2024

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate authorization of a user to query the "/api…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46892

Published Nov 12, 2024

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly invalidate sessions when the associated user is del…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46891

Published Nov 12, 2024

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly restrict the size of generated log files. This coul…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46890

Published Nov 12, 2024

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate input sent to specific endpoints of its we…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-46889

Published Nov 12, 2024

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application uses hard-coded cryptographic key material to obfuscate configuration…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46888

Published Nov 12, 2024

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly sanitize user provided paths for SFTP-based file up…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-48431

Published Dec 12, 2023

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected software does not correctly validate the response received by an UMC server. An attac…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48430

Published Dec 12, 2023

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The REST API of affected devices does not check the length of parameters in certain conditions…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-48429

Published Dec 12, 2023

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The Web UI of affected devices does not check the length of parameters in certain conditions.…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-48428

Published Dec 12, 2023

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The radius configuration mechanism of affected products does not correctly check uploaded cert…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-48427

Published Dec 12, 2023

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-45094

Published Jan 10, 2023

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affe…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-45093

Published Jan 10, 2023

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affe…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-45092

Published Jan 10, 2023

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affe…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-32222

Published Jul 14, 2022

A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circ…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 41 CVEsPage 1 of 2