Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-97255
HistoryDec 13, 2023 - 12:00 a.m.

Siemens SINEC INS Operating System Command Injection Vulnerability

2023-12-1300:00:00
China National Vulnerability Database
www.cnvd.org.cn
11
siemens
sinec ins
command injection
network services
industrial networks
vulnerability
denial of service
radius configuration

AI Score

7.9

Confidence

High

EPSS

0.001

Percentile

20.0%

SINEC INS (Infrastructure Network Services) is a web-based application that combines various network services in one tool. This simplifies the installation and management of all network services associated with industrial networks. Siemens SINEC INS suffers from an operating system command injection vulnerability due to the radius configuration mechanism of the affected product not properly checking uploaded certificates. An attacker could exploit this vulnerability to cause a denial of service condition or possibly execute commands on the system.

AI Score

7.9

Confidence

High

EPSS

0.001

Percentile

20.0%

Related for CNVD-2023-97255