Lucene search

K
cvelistSiemensCVELIST:CVE-2023-48431
HistoryDec 12, 2023 - 11:27 a.m.

CVE-2023-48431

2023-12-1211:27:23
CWE-754
siemens
www.cve.org
5
cve-2023-48431
sinec ins
software vulnerability
umc server
traffic manipulation

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H/E:P/RL:O/RC:C

AI Score

9.2

Confidence

High

EPSS

0.001

Percentile

25.7%

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected software does not correctly validate the response received by an UMC server. An attacker can use this to crash the affected software by providing and configuring a malicious UMC server or by manipulating the traffic from a legitimate UMC server (i.e. leveraging CVE-2023-48427).

CNA Affected

[
  {
    "vendor": "Siemens",
    "product": "SINEC INS",
    "versions": [
      {
        "version": "All versions < V1.0 SP2 Update 2",
        "status": "affected"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H/E:P/RL:O/RC:C

AI Score

9.2

Confidence

High

EPSS

0.001

Percentile

25.7%

Related for CVELIST:CVE-2023-48431