Executive brief
Siemens SINEC INS, a web-based tool used to manage industrial network services, contains a security flaw that allows authenticated users to execute unauthorized commands. By uploading files with specially crafted directory names, an attacker can take control of the underlying operating system. This could lead to a complete compromise of the network management tool, potentially impacting the availability and security of industrial network operations.
Technical details
An OS command injection vulnerability exists in the /api/sftp/uploadFiles endpoint of Siemens SINEC INS due to improper sanitization of user-provided directory names. An authenticated remote attacker can inject shell command payloads via crafted directory names during file upload operations. These payloads are stored and subsequently executed when directory listings are retrieved by the application. Successful exploitation allows for arbitrary command execution with the privileges of the 'sinecins' service user. Siemens has addressed this in SINEC INS V1.0 SP2 Update 6.
Affected products
- Siemens SINEC INS All versions < V1.0 SP2 Update 6
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory
- 2026-06-09: patched: Fixed in V1.0 SP2 Update 6