A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product, could potentially read and write arbitrary files from and to the device's file system. An attacker might leverage this to trigger remote code execution on the affected component.
References
Link | Resource |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: siemens
Published: 2023-01-10T11:39:41.994Z
Updated:
Reserved: 2022-11-09T14:32:46.476Z
Link: CVE-2022-45092
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-01-10T12:15:23.453
Modified: 2023-01-14T00:47:06.117
Link: CVE-2022-45092
JSON object: View
Redhat Information
No data.
CWE