A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate authorization of a user to query the "/api/sftp/users" endpoint. This could allow an authenticated remote attacker to gain knowledge about the list of configured users of the SFTP service and also modify that configuration.
History

Tue, 12 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens sinec Ins
Weaknesses CWE-276
CPEs cpe:2.3:a:siemens:sinec_ins:-:*:*:*:*:*:*:*
Vendors & Products Siemens
Siemens sinec Ins
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 Nov 2024 13:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate authorization of a user to query the "/api/sftp/users" endpoint. This could allow an authenticated remote attacker to gain knowledge about the list of configured users of the SFTP service and also modify that configuration.
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2024-11-12T12:49:45.831Z

Updated: 2024-11-12T14:19:46.429Z

Reserved: 2024-09-12T11:26:58.816Z

Link: CVE-2024-46894

cve-icon Vulnrichment

Updated: 2024-11-12T14:19:39.331Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-12T13:15:10.193

Modified: 2024-11-12T15:35:12.310

Link: CVE-2024-46894

cve-icon Redhat

No data.