Vulnerabilities (CVE)

Filtered by vendor Siemens Subscribe
Filtered by product Sinec Ins
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-48428 1 Siemens 1 Sinec Ins 2023-12-14 N/A 7.2 HIGH
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The radius configuration mechanism of affected products does not correctly check uploaded certificates. A malicious admin could upload a crafted certificate resulting in a denial-of-service condition or potentially issue commands on system level.
CVE-2023-48431 1 Siemens 1 Sinec Ins 2023-12-14 N/A 8.6 HIGH
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected software does not correctly validate the response received by an UMC server. An attacker can use this to crash the affected software by providing and configuring a malicious UMC server or by manipulating the traffic from a legitimate UMC server (i.e. leveraging CVE-2023-48427).