Machine-generated analysis · WAYSCloud LLM
The advisory states that SINEC INS before version 1.0 SP2 Update 6 is affected by an OS command injection vulnerability via the /api/sftp/uploadFiles endpoint, where crafted directory names can lead to arbitrary command execution.
Context
Siemens SINEC INS is an industrial network security solution used in critical infrastructure sectors including energy, transportation, and manufacturing. The advisory identifies multiple vulnerabilities, including OS command injection and path traversal, which could allow authenticated remote attackers to execute commands or access unauthorized files. The command injection vulnerability stems from improper input sanitization in a specific API endpoint. These issues are resolved in version 1.0 SP2 Update 6 or later.
Operator considerations
Check: Inventory all instances of Siemens SINEC INS to identify those running versions prior to 1.0 SP2 Update 6.
Patch: Update to Siemens SINEC INS version 1.0 SP2 Update 6 or later as recommended by the vendor.
Log: Monitor logs for unusual activity on the /api/sftp/uploadFiles endpoint, particularly from authenticated users.
SINEC INS before V1.0 SP2 Update 6 is affected by multiple vulnerabilities. Siemens has released a new version for SINEC INS and recommends to update to the latest version.
The following versions of Siemens SINEC INS are affected:
SINEC INS vers:intdot/
Read the full advisory on CISA →