Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 12 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:siemens:sinec_ins:*:-:*:*:*:*:*:* cpe:2.3:a:siemens:sinec_ins:1.0:sp1:*:*:*:*:*:* cpe:2.3:a:siemens:sinec_ins:1.0:sp2:*:*:*:*:*:* cpe:2.3:a:siemens:sinec_ins:1.0:sp2_update_1:*:*:*:*:*:* cpe:2.3:a:siemens:sinec_ins:1.0:sp2_update_2:*:*:*:*:*:* cpe:2.3:a:siemens:sinec_ins:1.0:sp2_update_3:*:*:*:*:*:* cpe:2.3:a:siemens:sinec_ins:1.0:sp2_update_4:*:*:*:*:*:* cpe:2.3:a:siemens:sinec_ins:1.0:sp2_update_5:*:*:*:*:*:* |
Tue, 09 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Weak Password Hashing with Static Salt in Siemens SINEC INS | |
| First Time appeared |
Siemens
Siemens sinec Ins |
|
| Vendors & Products |
Siemens
Siemens sinec Ins |
Tue, 09 Jun 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resulting in unauthorized access. | |
| Weaknesses | CWE-760 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2026-06-09T13:10:31.258Z
Reserved: 2026-05-18T09:37:25.766Z
Link: CVE-2026-46749
Updated: 2026-06-09T13:10:26.712Z
Status : Analyzed
Published: 2026-06-09T10:16:44.410
Modified: 2026-06-12T15:15:09.300
Link: CVE-2026-46749
No data.
OpenCVE Enrichment
Updated: 2026-06-09T11:30:03Z