Status: UPDATED
| Advisory ID: CVE-2026-46748
Key Details
| CVE | CVE-2026-46748 |
| CVSS Score / Version | 8.8 (High) / CVSS v3.1 |
| Updated | 2026-07-23 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Siemens sinec_ins and Siemens SINEC INS |
| Classified as | CWE-250 (Execution with Unnecessary Privileges) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a binary that is configured with the cap_dac_override capability. This capability allows the process to bypass file system permission checks, resulting in unrestricted file system access. This could allow a local attacker to escalate privileges leading to arbitrary file modification and gaining root privileges on the system. (NVD)
What to Do
Monitor Siemens's web page for any future patch releases. See vendor advisory link below.
References