Lucene search

K
nvd[email protected]NVD:CVE-2022-45093
HistoryJan 10, 2023 - 12:15 p.m.

CVE-2022-45093

2023-01-1012:15:23
CWE-22
web.nvd.nist.gov
4
sinec ins
remote attacker
web based management
sftp server
arbitrary files
remote code execution
vulnerability

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.002

Percentile

58.2%

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product as well as with access to the SFTP server of the affected product (22/tcp), could potentially read and write arbitrary files from and to the device’s file system. An attacker might leverage this to trigger remote code execution on the affected component.

Affected configurations

Nvd
Node
siemenssinec_insRange<1.0
OR
siemenssinec_insMatch1.0-
OR
siemenssinec_insMatch1.0sp1
OR
siemenssinec_insMatch1.0sp2
VendorProductVersionCPE
siemenssinec_ins*cpe:2.3:a:siemens:sinec_ins:*:*:*:*:*:*:*:*
siemenssinec_ins1.0cpe:2.3:a:siemens:sinec_ins:1.0:-:*:*:*:*:*:*
siemenssinec_ins1.0cpe:2.3:a:siemens:sinec_ins:1.0:sp1:*:*:*:*:*:*
siemenssinec_ins1.0cpe:2.3:a:siemens:sinec_ins:1.0:sp2:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.002

Percentile

58.2%

Related for NVD:CVE-2022-45093