A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resulting in unauthorized access.
| Vendor | Product | Versions |
|---|---|---|
| siemens | sinec ins | 0 |
Updated affected versions to include 1.0 SP2 Update 5 and confirmed no exploit is available.
Initial creation