CVE-2024-46894: Siemens Sinec Ins

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate authorization of a user to query the "/api/sftp/users" endpoint. This could allow an authenticated remote attacker to gain knowledge about the list of configured users of the SFTP service and also modify that configuration.

Affected products

  • Siemens Sinec Ins: up to and including 1.0; version 1.0 only

Published 2024-11-12. Last modified 2026-06-17.