Lucene search

K
cvelistSiemensCVELIST:CVE-2023-48430
HistoryDec 12, 2023 - 11:27 a.m.

CVE-2023-48430

2023-12-1211:27:22
CWE-392
siemens
www.cve.org
5
vulnerability
sinec ins
rest api
parameters
crash
server restart

CVSS3

2.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C

AI Score

4

Confidence

High

EPSS

0

Percentile

13.3%

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The REST API of affected devices does not check the length of parameters in certain conditions. This allows a malicious admin to crash the server by sending a crafted request to the API. The server will automatically restart.

CNA Affected

[
  {
    "vendor": "Siemens",
    "product": "SINEC INS",
    "versions": [
      {
        "version": "All versions < V1.0 SP2 Update 2",
        "status": "affected"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

2.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C

AI Score

4

Confidence

High

EPSS

0

Percentile

13.3%

Related for CVELIST:CVE-2023-48430