CVE-2024-46894
- EPSS 0.08%
- Veröffentlicht 12.11.2024 13:15:10
- Zuletzt bearbeitet 20.08.2025 19:09:37
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate authorization of a user to query the "/api/sftp/users" endpoint. This could allow an authenticated remote attacke...
CVE-2024-46892
- EPSS 0.08%
- Veröffentlicht 12.11.2024 13:15:09
- Zuletzt bearbeitet 13.11.2024 23:13:06
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly invalidate sessions when the associated user is deleted or disabled or their permissions are modified. This could allow an...
CVE-2024-46891
- EPSS 0.2%
- Veröffentlicht 12.11.2024 13:15:09
- Zuletzt bearbeitet 20.08.2025 19:11:08
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly restrict the size of generated log files. This could allow an unauthenticated remote attacker to trigger a large amount of...
CVE-2024-46890
- EPSS 0.83%
- Veröffentlicht 12.11.2024 13:15:09
- Zuletzt bearbeitet 13.11.2024 23:12:39
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate input sent to specific endpoints of its web API. This could allow an authenticated remote attacker with high priv...
CVE-2024-46889
- EPSS 0.1%
- Veröffentlicht 12.11.2024 13:15:09
- Zuletzt bearbeitet 13.11.2024 23:11:58
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application uses hard-coded cryptographic key material to obfuscate configuration files. This could allow an attacker to learn that cryptographic key ma...
CVE-2024-46888
- EPSS 1.53%
- Veröffentlicht 12.11.2024 13:15:08
- Zuletzt bearbeitet 13.11.2024 23:11:24
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly sanitize user provided paths for SFTP-based file up- and downloads. This could allow an authenticated remote attacker to m...
CVE-2023-48429
- EPSS 0.12%
- Veröffentlicht 12.12.2023 12:15:15
- Zuletzt bearbeitet 21.11.2024 08:31:42
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The Web UI of affected devices does not check the length of parameters in certain conditions. This allows a malicious admin to crash the server by sending a crafted ...
CVE-2023-48430
- EPSS 0.1%
- Veröffentlicht 12.12.2023 12:15:15
- Zuletzt bearbeitet 21.11.2024 08:31:42
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The REST API of affected devices does not check the length of parameters in certain conditions. This allows a malicious admin to crash the server by sending a crafte...
CVE-2023-48431
- EPSS 0.17%
- Veröffentlicht 12.12.2023 12:15:15
- Zuletzt bearbeitet 21.11.2024 08:31:42
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected software does not correctly validate the response received by an UMC server. An attacker can use this to crash the affected software by providing and config...
CVE-2023-48428
- EPSS 0.07%
- Veröffentlicht 12.12.2023 12:15:14
- Zuletzt bearbeitet 21.11.2024 08:31:42
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The radius configuration mechanism of affected products does not correctly check uploaded certificates. A malicious admin could upload a crafted certificate resultin...