CVE-2022-45092 is a critical path traversal vulnerability affecting all versions of Siemens SINEC INS prior to V1.0 SP2 Update 1. An authenticated remote attacker can exploit this flaw via the web-based management interface (443/tcp) to read and write arbitrary files on the device's file system. This high-severity vulnerability, rated 8.8 CVSS, could lead to remote code execution, allowing an attacker full control over the affected component. While there is no known public exploit code or active exploitation, the vulnerability has garnered some community discussion, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0CPE matchmatch criteria | cpe:2.3:a:siemens:sinec_ins:*:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:siemens:sinec_ins:1.0:-:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:siemens:sinec_ins:1.0:sp1:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:siemens:sinec_ins:1.0:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.