CVE Vulnerabilities

CVE-2023-48427

Improper Certificate Validation

Published: Dec 12, 2023 | Modified: Dec 14, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the UMC server as well as to manipulate responses, potentially allowing an attacker to escalate privileges.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Sinec_ins Siemens * 1.0 (excluding)
Sinec_ins Siemens 1.0 (including) 1.0 (including)
Sinec_ins Siemens 1.0-sp1 (including) 1.0-sp1 (including)
Sinec_ins Siemens 1.0-sp2 (including) 1.0-sp2 (including)
Sinec_ins Siemens 1.0-sp2_update_1 (including) 1.0-sp2_update_1 (including)

Potential Mitigations

References