CVE-2023-48430
Published: 12 December 2023
Summary
CVE-2023-48430 is a low-severity Missing Report of Error Condition (CWE-392) vulnerability in Siemens Sinec Ins. Its CVSS base score is 2.7 (Low).
Operationally, ranked at the 27.5th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-52481
Vulnerability details
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The REST API of affected devices does not check the length of parameters in certain conditions. This allows a malicious admin to crash the server…
more
by sending a crafted request to the API. The server will automatically restart.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Mandates alerting on audit failures, directly providing the missing report of the error condition.
Reporting the security and privacy status to organizational officials ensures monitoring and assessment results are communicated rather than omitted.
Requires reporting and escalation of error conditions and incidents per documented procedures.
IR testing would expose missing error reporting that prevents timely incident detection and response.
Offers direct support for reporting incidents, addressing the failure to report error conditions or security events.
Includes explicit reporting of security status and analysis results, addressing missing reports of error or monitoring conditions.