Description
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The radius configuration mechanism of affected products does not correctly check uploaded certificates. A malicious admin could upload a crafted certificate resulting in a denial-of-service condition or potentially issue commands on system level.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-52479 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The radius configuration mechanism of affected products does not correctly check uploaded certificates. A malicious admin could upload a crafted certificate resulting in a denial-of-service condition or potentially issue commands on system level. |
References
History
No history.
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2026-02-25T16:34:35.052Z
Reserved: 2023-11-16T16:30:40.849Z
Link: CVE-2023-48428
No data.
Status : Modified
Published: 2023-12-12T12:15:14.873
Modified: 2024-11-21T08:31:42.200
Link: CVE-2023-48428
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD