← Vulnerability feed

Vulnerability record · CVE-2023-48427 · published 12 December 2023

CVE-2023-48427: Siemens sinec ins improper certificate validation vulnerability

Siemens · Sinec Ins

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the UMC server as well as to manipulate responses, potentially allowing an attacker to escalate privileges.

9.8 CVSS 3.1 Critical EPSS 0.38% · top 70.3% CWE-295 · Improper certificate validation
9.8CVSS 3.1 base score
0.38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the UMC server as well as to manipulate responses, potentially allowing an attacker to escalate privileges.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-48427 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.4CVE-2024-46890Siemens sinec ins os command injection vulnerabilityA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate input sent t…EPSS 0.74%9.4CVE-2024-46888Siemens sinec ins path traversal vulnerabilityA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly sanitize user provide…EPSS 0.92%9.1CVE-2022-35255Nodejs node.js vulnerabilityA weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in sr…EPSS 1.9%9.1CVE-2021-22945Haxx libcurl double free vulnerabilityWhen sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory a…EPSS 6.7%8.8CVE-2022-45092Siemens sinec ins path traversal vulnerabilityA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Ma…EPSS 31%8.8CVE-2022-45093Siemens sinec ins path traversal vulnerabilityA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Ma…EPSS 1.2%8.8CVE-2022-45094Siemens sinec ins command injection vulnerabilityA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Ma…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2023-48427), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.