Siemens SINEC INS

2026-06-23T19:23:25Zb48bb315051dedffbd8d1efe0a015412f23e5f0e0ad7d38277e3bc9645c15ee0
ICSOTabbarbitrary-file-uploadb&rcisacleartext-storagecommand-injectioncritical-infrastructuredenial-of-servicehubbelllinux-kernelmissing-authenticationopensslpatching-recommendedpath-traversalprivilege-escalationremote-code-executionsiemens

What happened

CISA published a multi-vendor ICS advisory (26 Jun 2026) covering multiple high-impact vulnerabilities across critical infrastructure products. Key issues include: Siemens SINEC INS (pre‑V1.0 SP2 Update 6) with command injection via /api/sftp/uploadFiles, path traversal, privilege escalation, and weak hashing (CVE-2026-46746); Hubbell Aclara Metrum Cellular Web Interface with missing authentication on critical functions enabling device takeover/disruption (CVE-2026-1840); Siemens products using OpenSSL affected by a stack-based buffer overflow allowing DoS or potential RCE (CVE-2025-15467); SI

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ics_advisories
Record identifier
b48bb315051dedffbd8d1efe0a015412f23e5f0e0ad7d38277e3bc9645c15ee0
Enrichment time
2026-06-23T19:23:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.