CVE-2026-46747

EUVD-2026-35384
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not properly sanitize path input in the `GET /api/sftp/uploadFiles` endpoint used for directory listing. This allows path traversal through crafted input, enabling access to unintended file system locations.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
Affected Products (NVD)
VendorProductVersion
siemenssinec_ins
𝑥
≤ 1.0
siemenssinec_ins
1.0:sp1
siemenssinec_ins
1.0:sp2
siemenssinec_ins
1.0:sp2_update_1
siemenssinec_ins
1.0:sp2_update_2
siemenssinec_ins
1.0:sp2_update_3
siemenssinec_ins
1.0:sp2_update_4
siemenssinec_ins
1.0:sp2_update_5
𝑥
= Vulnerable software versions