PT-2024-8709 · Siemens · Sinec Ins

Published

2024-11-12

·

Updated

2024-11-12

·

CVE-2024-46891

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SINEC INS versions prior to V1.0 SP2 Update 3
Description A vulnerability has been identified in the affected application where it does not properly restrict the size of generated log files. This could allow an unauthenticated remote attacker to trigger a large amount of logged events, exhausting the system's resources and creating a denial of service condition.
Recommendations For versions prior to V1.0 SP2 Update 3, update to V1.0 SP2 Update 3 or later to resolve the issue. As a temporary workaround, consider implementing restrictions on log file size to prevent excessive resource utilization. Restrict access to the logging mechanism to minimize the risk of exploitation.

Fix

Out of bounds Read

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2024-10311
CVE-2024-46891

Affected Products

Sinec Ins