The vendor explicitly identifies these products as affected by this CVE.
- SINEC INS
- Summary
- A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.16.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.
- Remediation
- Update to V1.0 SP2 Update 1 or later version
