Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-97256
HistoryDec 13, 2023 - 12:00 a.m.

Siemens SINEC INS Certificate Validation Improperity Vulnerability

2023-12-1300:00:00
China National Vulnerability Database
www.cnvd.org.cn
13
siemens
sinec ins
certificate validation
vulnerability
data interception
umc server
privilege escalation
industrial networks

AI Score

6.9

Confidence

Low

EPSS

0.001

Percentile

25.7%

SINEC INS (Infrastructure Network Services) is a web-based application that combines various network services in one tool. This simplifies the installation and management of all network services associated with industrial networks. Siemens SINEC INS suffers from a Certificate Validation Improperity vulnerability, which is due to the affected product failing to properly validate the certificate of the configured UMC server. An attacker could exploit the vulnerability to be able to intercept credentials sent to the UMC server and manipulate the response to escalate privileges.

AI Score

6.9

Confidence

Low

EPSS

0.001

Percentile

25.7%

Related for CNVD-2023-97256