Lucene search

K
cveSiemensCVE-2023-48431
HistoryDec 12, 2023 - 12:15 p.m.

CVE-2023-48431

2023-12-1212:15:15
CWE-754
siemens
web.nvd.nist.gov
19
cve-2023-48431
sinec ins
vulnerability
umc server
nvd

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

AI Score

7.1

Confidence

High

EPSS

0.001

Percentile

25.7%

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected software does not correctly validate the response received by an UMC server. An attacker can use this to crash the affected software by providing and configuring a malicious UMC server or by manipulating the traffic from a legitimate UMC server (i.e. leveraging CVE-2023-48427).

Affected configurations

Nvd
Node
siemenssinec_insRange<1.0
OR
siemenssinec_insMatch1.0-
OR
siemenssinec_insMatch1.0sp1
OR
siemenssinec_insMatch1.0sp2
OR
siemenssinec_insMatch1.0sp2_update_1
VendorProductVersionCPE
siemenssinec_ins*cpe:2.3:a:siemens:sinec_ins:*:*:*:*:*:*:*:*
siemenssinec_ins1.0cpe:2.3:a:siemens:sinec_ins:1.0:-:*:*:*:*:*:*
siemenssinec_ins1.0cpe:2.3:a:siemens:sinec_ins:1.0:sp1:*:*:*:*:*:*
siemenssinec_ins1.0cpe:2.3:a:siemens:sinec_ins:1.0:sp2:*:*:*:*:*:*
siemenssinec_ins1.0cpe:2.3:a:siemens:sinec_ins:1.0:sp2_update_1:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Siemens",
    "product": "SINEC INS",
    "versions": [
      {
        "version": "All versions < V1.0 SP2 Update 2",
        "status": "affected"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

AI Score

7.1

Confidence

High

EPSS

0.001

Percentile

25.7%

Related for CVE-2023-48431