CVE-2023-48428
12.12.2023, 12:15
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The radius configuration mechanism of affected products does not correctly check uploaded certificates. A malicious admin could upload a crafted certificate resulting in a denial-of-service condition or potentially issue commands on system level.
Vendor | Product | Version |
---|---|---|
siemens | sinec_ins | 𝑥 < 1.0 |
siemens | sinec_ins | 1.0 |
siemens | sinec_ins | 1.0:sp1 |
siemens | sinec_ins | 1.0:sp2 |
siemens | sinec_ins | 1.0:sp2_update_1 |
𝑥
= Vulnerable software versions