Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2835 articles · 161804 vulns · 36/41 feeds (7d)
← Back to list
7.5
CVE-2026-46749PATCHED
siemens · sinec ins

CVE-2026-46749: A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a pas

Description

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resulting in unauthorized access.

Affected Products

VendorProductVersions
siemenssinec ins0

References

  • https://cert-portal.siemens.com/productcert/html/ssa-860189.html

Related News (1 articles)

Tier C
VulDB9h ago
CVE-2026-46749 | Siemens SINEC INS up to 1.0 SP2 Update 5 hash predictable salt (ssa-860189)
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
V1.0 SP2 Update 6
CWECWE-760
PublishedJun 9, 2026
Last enriched8h agov2
Trending Score31
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2025-40808EXP
CVE-2025-40808: A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions),
Trending: 52
HIGHCVE-2026-46748EXP
CVE-2026-46748: A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a bina
Trending: 50
HIGHCVE-2026-46746EXP
CVE-2026-46746: A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly s
Trending: 50
MEDIUMCVE-2026-46747EXP
CVE-2026-46747: A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not p
Trending: 41
HIGHCVE-2026-24349
CVE-2026-24349: A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Run
Trending: 37

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 9, 2026
Discovered by ZDM
Jun 9, 2026
Updated: affectedVersions
Jun 9, 2026
Patch Available
Jun 9, 2026

Version History

v2
Last enriched 8h ago
v2Tier C8h ago

Updated affected versions to include 1.0 SP2 Update 5 and confirmed no exploit is available.

affectedVersions
via VulDB
v19h ago

Initial creation