CVE-2024-46891
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Nov 12, 2024
CWE ID 125
CWE ID 400
Summary
CVE-2024-46891 is a newly identified vulnerability affecting all versions of SINEC INS before V1.0 SP2 Update 3. The issue lies in the application's failure to limit the size of generated log files, making it susceptible to denial of service attacks. An unauthenticated remote attacker can trigger a large number of logged events, exhausting the system's resources and causing a denial of service condition. The vulnerability poses a significant risk to system availability and should be addressed with the recommended update as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.