No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 09 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens sinec Ins |
|
| Vendors & Products |
Siemens
Siemens sinec Ins |
Tue, 09 Jun 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly sanitize user input in the /api/sftp/uploadFiles endpoint, allowing the injection of shell command payloads via crafted directory names. These payloads are stored and executed when directory listings are retrieved. This could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system with the privileges of the affected service user (sinecins). | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2026-06-09T15:12:58.585Z
Reserved: 2026-05-18T09:37:25.766Z
Link: CVE-2026-46746
Updated: 2026-06-09T15:12:08.242Z
Status : Awaiting Analysis
Published: 2026-06-09T10:16:44.000
Modified: 2026-06-09T13:49:39.993
Link: CVE-2026-46746
No data.
OpenCVE Enrichment
Updated: 2026-06-09T11:30:03Z