Description
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The REST API of affected devices does not check the length of parameters in certain conditions. This allows a malicious admin to crash the server by sending a crafted request to the API. The server will automatically restart.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-52481 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The REST API of affected devices does not check the length of parameters in certain conditions. This allows a malicious admin to crash the server by sending a crafted request to the API. The server will automatically restart. |
References
History
No history.
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2026-02-25T16:34:34.289Z
Reserved: 2023-11-16T16:30:40.849Z
Link: CVE-2023-48430
No data.
Status : Modified
Published: 2023-12-12T12:15:15.433
Modified: 2024-11-21T08:31:42.457
Link: CVE-2023-48430
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD