PT-2026-47733 · Siemens · Sinec Ins
CVE-2026-46747
·
Published
2026-06-09
·
Updated
2026-06-09
CVSS v2.0
6.0
Medium
| Vector | AV:L/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SINEC INS versions prior to V1.0 SP2 Update 6
Description
The application fails to properly sanitize path input in the 'GET /api/sftp/uploadFiles' endpoint used for directory listing. This allows path traversal, a technique used to access files and directories that are stored outside the web root folder, by using crafted input to reach unintended file system locations.
Recommendations
Update to V1.0 SP2 Update 6 or a newer version.
As a temporary workaround, restrict access to the 'GET /api/sftp/uploadFiles' endpoint to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sinec Ins