A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The Web UI of affected devices does not check the length of parameters in certain conditions. This allows a malicious admin to crash the server by sending a crafted request to the server. The server will automatically restart.
The product does not properly check when a function or operation returns a value that is legitimate for the function, but is not expected by the product.
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
Link | Tags |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-077170.pdf | patch vendor advisory |