CVE-2024-46891: Siemens Sinec Ins

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly restrict the size of generated log files. This could allow an unauthenticated remote attacker to trigger a large amount of logged events to exhaust the system's resources and create a denial of service condition.

Affected products

  • Siemens Sinec Ins: up to and including 1.0; version 1.0 only

Published 2024-11-12. Last modified 2026-06-17.