CVE-2023-48429: Siemens Sinec Ins
Low severity, CVSS 2.7. EPSS: 0.6% chance of exploitation in the next 30 days.
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The Web UI of affected devices does not check the length of parameters in certain conditions. This allows a malicious admin to crash the server by sending a crafted request to the server. The server will automatically restart.
Affected products
- Siemens Sinec Ins: before 1.0 (fixed in 1.0); version 1.0 only
Published 2023-12-12. Last modified 2026-06-17.