Junglewise Threat Intelligence

CVE-2026-46749: Siemens SINEC INS weak password hashing using hardcoded salt

CVE-2026-46749 · Severity: high · CVSS 7.5 · Published 2026-06-09

Technologies: Siemens Sinec Ins. Vendors: Siemens.

Executive brief

Siemens SINEC INS, a tool used to manage industrial network services, uses a weak method for protecting user passwords. Because the system uses a single shared secret and low-security settings to scramble passwords, an attacker with access to the system could more easily crack those passwords. This could lead to unauthorized access to the network management tool and potential disruption of industrial operations.

Technical details

The vulnerability (CWE-760) exists in the password hashing mechanism of Siemens SINEC INS. The application utilizes a static, hardcoded salt that is identical across all user accounts and installations, combined with a low iteration count for the hashing algorithm. An attacker with local access and high privileges could exploit this to perform offline brute-force or rainbow table attacks to recover plaintext passwords. This is particularly dangerous in environments where the same credentials might be reused across different systems. Siemens has addressed this in SINEC INS V1.0 SP2 Update 6.

Affected products

  • Siemens SINEC INS All versions < V1.0 SP2 Update 6

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory
  • 2026-06-09: patched: Fixed in V1.0 SP2 Update 6

References

Related threats