A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product, could potentially inject commands into the dhcpd configuration of the affected product. An attacker might leverage this to trigger remote code execution on the affected component.
References
Link | Resource |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: siemens
Published: 2023-01-10T11:39:44.116Z
Updated:
Reserved: 2022-11-09T14:32:46.476Z
Link: CVE-2022-45094
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-01-10T12:15:23.590
Modified: 2023-01-14T00:43:06.910
Link: CVE-2022-45094
JSON object: View
Redhat Information
No data.
CWE