Lucene search

K
cvelistSiemensCVELIST:CVE-2022-45092
HistoryJan 10, 2023 - 11:39 a.m.

CVE-2022-45092

2023-01-1011:39:41
CWE-22
siemens
www.cve.org
8
vulnerability
sinec ins
remote code execution
file system access

CVSS3

9.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C

AI Score

9.6

Confidence

High

EPSS

0.002

Percentile

58.2%

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product, could potentially read and write arbitrary files from and to the device’s file system. An attacker might leverage this to trigger remote code execution on the affected component.

CNA Affected

[
  {
    "vendor": "Siemens",
    "product": "SINEC INS",
    "versions": [
      {
        "version": "All versions < V1.0 SP2 Update 1",
        "status": "affected"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

9.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C

AI Score

9.6

Confidence

High

EPSS

0.002

Percentile

58.2%

Related for CVELIST:CVE-2022-45092