Siemens SINEC INS
2026-06-23T19:23:25Z•b48bb315051dedffbd8d1efe0a015412f23e5f0e0ad7d38277e3bc9645c15ee0
ICSOTabbarbitrary-file-uploadb&rcisacleartext-storagecommand-injectioncritical-infrastructuredenial-of-servicehubbelllinux-kernelmissing-authenticationopensslpatching-recommendedpath-traversalprivilege-escalationremote-code-executionsiemens
What happened
CISA published a multi-vendor ICS advisory (26 Jun 2026) covering multiple high-impact vulnerabilities across critical infrastructure products. Key issues include: Siemens SINEC INS (pre‑V1.0 SP2 Update 6) with command injection via /api/sftp/uploadFiles, path traversal, privilege escalation, and weak hashing (CVE-2026-46746); Hubbell Aclara Metrum Cellular Web Interface with missing authentication on critical functions enabling device takeover/disruption (CVE-2026-1840); Siemens products using OpenSSL affected by a stack-based buffer overflow allowing DoS or potential RCE (CVE-2025-15467); SI
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ics_advisories
- Record identifier
- b48bb315051dedffbd8d1efe0a015412f23e5f0e0ad7d38277e3bc9645c15ee0
- Enrichment time
- 2026-06-23T19:23:25Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.