← Back to browse · API

CVE-2022-45092

Severity
CRITICAL
CVSS
9.9
EPSS
0.31443
Risk score
50.61
CISA KEV
No
PoC
No
Published
2023-01-10
Modified
2025-05-27
First seen
2026-08-07
Aliases
EUVD-2022-48013, GHSA-JPC4-X6X2-7PM8
Products
Siemens:SINEC INS All versions < V1.0 SP2 Update 1
Sources
euvd EUVD-2022-48013

Description

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product, could potentially read and write arbitrary files from and to the device's file system. An attacker might leverage this to trigger remote code execution on the affected component.

References