CVE-2026-46749 Details
Description
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resulting in unauthorized access.
A vulnerability exists in Siemens SINEC INS versions prior to V1.0 SP2 Update 6, due to a password hashing method that employs a static, hardcoded salt shared among all users and installations, combined with an inadequate number of iterations. This flaw could enable an attacker to efficiently recover user passwords through brute-force or precomputed attacks, potentially leading to unauthorized access.
Users are advised to update to Siemens SINEC INS V1.0 SP2 Update 6 or a later version. For more information, visit the Siemens Industry Support page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-860189.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-760 | Use of a One-Way Hash with a Predictable Salt | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| siemens sinec ins | <= 1.0 1.0 sp1 1.0 sp2 1.0 sp2_update_1 1.0 sp2_update_2 1.0 sp2_update_3 1.0 sp2_update_4 1.0 sp2_update_5 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | Initial Analysis | [email protected] |
| Jun 9, 2026 | New CVE Received | [email protected] |