A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly sanitize user provided paths for SFTP-based file up- and downloads. This could allow an authenticated remote attacker to manipulate arbitrary files on the filesystem and achieve arbitrary code execution on the device.

Barracuda Blog


The Barracuda blog brings you the latest news, research, and insights you can’t get anywhere else.

Highlights

  • A thorough blog covering all aspect of cybersecurity.
Listed: