Show filters
48 Total Results
Displaying 11-20 of 48
Sort by:
Attacker Value
Unknown
CVE-2024-46888
Disclosure Date: November 12, 2024 (last updated November 14, 2024)
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly sanitize user provided paths for SFTP-based file up- and downloads. This could allow an authenticated remote attacker to manipulate arbitrary files on the filesystem and achieve arbitrary code execution on the device.
0
Attacker Value
Unknown
CVE-2023-48431
Disclosure Date: December 12, 2023 (last updated December 15, 2023)
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected software does not correctly validate the response received by an UMC server. An attacker can use this to crash the affected software by providing and configuring a malicious UMC server or by manipulating the traffic from a legitimate UMC server (i.e. leveraging CVE-2023-48427).
0
Attacker Value
Unknown
CVE-2023-48430
Disclosure Date: December 12, 2023 (last updated December 15, 2023)
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The REST API of affected devices does not check the length of parameters in certain conditions. This allows a malicious admin to crash the server by sending a crafted request to the API. The server will automatically restart.
0
Attacker Value
Unknown
CVE-2023-48429
Disclosure Date: December 12, 2023 (last updated December 15, 2023)
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The Web UI of affected devices does not check the length of parameters in certain conditions. This allows a malicious admin to crash the server by sending a crafted request to the server. The server will automatically restart.
0
Attacker Value
Unknown
CVE-2023-48428
Disclosure Date: December 12, 2023 (last updated December 15, 2023)
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The radius configuration mechanism of affected products does not correctly check uploaded certificates. A malicious admin could upload a crafted certificate resulting in a denial-of-service condition or potentially issue commands on system level.
0
Attacker Value
Unknown
CVE-2023-48427
Disclosure Date: December 12, 2023 (last updated December 15, 2023)
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the UMC server as well as to manipulate responses, potentially allowing an attacker to escalate privileges.
0
Attacker Value
Unknown
CVE-2022-45094
Disclosure Date: January 10, 2023 (last updated October 08, 2023)
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product, could potentially inject commands into the dhcpd configuration of the affected product. An attacker might leverage this to trigger remote code execution on the affected component.
0
Attacker Value
Unknown
CVE-2022-45093
Disclosure Date: January 10, 2023 (last updated October 08, 2023)
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product as well as with access to the SFTP server of the affected product (22/tcp), could potentially read and write arbitrary files from and to the device's file system. An attacker might leverage this to trigger remote code execution on the affected component.
0
Attacker Value
Unknown
CVE-2022-45092
Disclosure Date: January 10, 2023 (last updated October 08, 2023)
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product, could potentially read and write arbitrary files from and to the device's file system. An attacker might leverage this to trigger remote code execution on the affected component.
0
Attacker Value
Unknown
CVE-2022-35256
Disclosure Date: December 05, 2022 (last updated October 08, 2023)
The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.
0