Lucene search

K
cvelistSiemensCVELIST:CVE-2023-48427
HistoryDec 12, 2023 - 11:27 a.m.

CVE-2023-48427

2023-12-1211:27:18
CWE-295
siemens
www.cve.org
7
vulnerability
sinec ins
credential interception
privilege escalation
certificate validation
umc server

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

AI Score

9.4

Confidence

High

EPSS

0.001

Percentile

25.7%

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the UMC server as well as to manipulate responses, potentially allowing an attacker to escalate privileges.

CNA Affected

[
  {
    "vendor": "Siemens",
    "product": "SINEC INS",
    "versions": [
      {
        "version": "All versions < V1.0 SP2 Update 2",
        "status": "affected"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

AI Score

9.4

Confidence

High

EPSS

0.001

Percentile

25.7%

Related for CVELIST:CVE-2023-48427