CVE-2024-46891

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Nov 12, 2024
CWE ID 125
CWE ID 400

Summary

CVE-2024-46891 is a newly identified vulnerability affecting all versions of SINEC INS before V1.0 SP2 Update 3. The issue lies in the application's failure to limit the size of generated log files, making it susceptible to denial of service attacks. An unauthenticated remote attacker can trigger a large number of logged events, exhausting the system's resources and causing a denial of service condition. The vulnerability poses a significant risk to system availability and should be addressed with the recommended update as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share