A successful login to SINEC INS before V1.0 SP2 Update 6 can cross from the web app into the host itself. The issue is not just bad input handling at the interface; one flaw can turn the service account into a command runner on the underlying operating system, and another opens unintended file-system access.
CISA says Siemens SINEC INS before V1.0 SP2 Update 6 is affected by multiple flaws, including authenticated OS command injection, path traversal, excessive privileges, and weak password hashing. Siemens has released V1.0 SP2 Update 6, and the affected footprint includes critical manufacturing, transportation, energy, healthcare, financial services, and government deployments worldwide.