Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-97252
HistoryDec 13, 2023 - 12:00 a.m.

Siemens SINEC INS Denial of Service Vulnerability (CNVD-2023-97252)

2023-12-1300:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
siemens sinec ins
denial of service
vulnerability
validation failure
umc server
manipulating traffic
industrial networks

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

25.7%

SINEC INS (Infrastructure Network Services) is a web-based application that combines various network services in one tool. This simplifies the installation and management of all network services associated with industrial networks. A denial of service vulnerability exists in Siemens SINEC INS due to a failure of the affected software to properly validate responses received by the UMC server. An attacker could exploit this vulnerability to crash the affected software by provisioning and configuring a malicious UMC server, or by manipulating traffic from a legitimate UMC server (i.e., by leveraging CVE-2023-48427).

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

25.7%

Related for CNVD-2023-97252