CVE-2026-46749
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resulting in unauthorized access.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 7.5
- CVSS vector
- CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H
- EPSS probability
- 0.12%
- CWE
- CWE-760
- Published
- 2026-06-09
- Last modified
- 2026-06-09
Affected products
- Siemens SINEC INS
Weakness type
Related vulnerabilities
- CVE-2026-9370 — ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecretKeySaltGenerator hash predictable salt
- CVE-2025-9290 — Authentication Weakness on Omada Controllers, Gateways and Access Points
- CVE-2024-13951 — One way hash with predictable salt
- CVE-2025-26486 — Broken or Risky Cryptographic Algorithm, Use of Password Hash...
- CVE-2023-22599
- CVE-2021-38314 — Gutenberg Template Library & Redux Framework <= 4.2.11 Sensitive Information Disclosure
- CVE-2020-28214 — A CWE-760: Use of a One-Way Hash with a Predictable Salt vulnerability exists in Modicon M221 (all...
- CVE-2018-5552 — DocuTrac DTISQLInstaller.exe Hard-Coded Salt