← Vulnerability feed

Vulnerability record · CVE-2024-46890 · published 12 November 2024

CVE-2024-46890: Siemens sinec ins os command injection vulnerability

Siemens · Sinec Ins

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate input sent to specific endpoints of its web API. This could allow an authenticated remote attacker with high privileges on the application to execute arbitrary code on the underlying OS.

9.4 CVSS 4.0 Critical EPSS 0.74% · top 47.2% CWE-78 · OS command injection
9.4CVSS 4.0 base score
0.74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate input sent to specific endpoints of its web API. This could allow an authenticated remote attacker with high privileges on the application to execute arbitrary code on the underlying OS.

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-46890 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.8CVE-2023-48427Siemens sinec ins improper certificate validation vulnerabilityA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of th…EPSS 0.38%9.4CVE-2024-46888Siemens sinec ins path traversal vulnerabilityA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly sanitize user provide…EPSS 0.92%9.1CVE-2022-35255Nodejs node.js vulnerabilityA weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in sr…EPSS 1.9%9.1CVE-2021-22945Haxx libcurl double free vulnerabilityWhen sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory a…EPSS 6.7%8.8CVE-2022-45092Siemens sinec ins path traversal vulnerabilityA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Ma…EPSS 31%8.8CVE-2022-45093Siemens sinec ins path traversal vulnerabilityA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Ma…EPSS 1.2%8.8CVE-2022-45094Siemens sinec ins command injection vulnerabilityA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Ma…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2024-46890), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.