CVE-2024-46890

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Nov 12, 2024
Updated: Nov 13, 2024
CWE ID 78

Summary

CVE-2024-46890 is a newly identified vulnerability affecting all versions of SINEC INS prior to V1.0 SP2 Update 3. The issue lies in the application's web API, which fails to validate input sent to certain endpoints. A successful exploitation of this vulnerability enables an authenticated attacker with high privileges to execute arbitrary code on the underlying OS. The implications of this vulnerability pose a significant threat to system security and stability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share