# CVE-2023-48429

## Summary

- **CVE ID:** CVE-2023-48429
- **Severity:** LOW
- **CVSS Score:** 2.7 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C)
- **CWE:** CWE-394
- **Published:** Dec 12, 2023
- **Last Modified:** Mar 13, 2026

## Description

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The Web UI of affected devices does not check the length of parameters in certain conditions. This allows a malicious admin to crash the server by sending a crafted request to the server. The server will automatically restart.

## Affected Products

- Siemens — SINEC INS (All versions < V1.0 SP2 Update 2)

## References

- [CNA](https://cert-portal.siemens.com/productcert/pdf/ssa-077170.pdf)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.12%
- **EPSS Percentile:** 30.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._