9.8

CVE-2023-48427

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the UMC server as well as to manipulate responses, potentially allowing an attacker to escalate privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Siemens ≫ Sinec Ins Version < 1.0
Siemens ≫ Sinec Ins Version 1.0 Update -
Siemens ≫ Sinec Ins Version 1.0 Update sp1
Siemens ≫ Sinec Ins Version 1.0 Update sp2
Siemens ≫ Sinec Ins Version 1.0 Update sp2_update_1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.299
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Siemens 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

https://cert-portal.siemens.com/productcert/pdf/ssa-077170.pdf
Patch
Vendor Advisory