CVE-2022-45092
critical · 9.9A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product, could potentially read and write arbitrary files from and to the device's file system. An attacker might leverage this to trigger remote code execution on the affected component.
9.9
CVSS
31.4%
EPSS (exploit prob.)
98th
EPSS percentile
2023-01-10
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| siemens | sinec_ins | < 1.0 |
| siemens | sinec_ins | 1.0 |
| siemens | sinec_ins | 1.0 |
| siemens | sinec_ins | 1.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-45092