CVE-2021-33721: OS Command Injection
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2). The affected application incorrectly neutralizes special elements when creating batch operations which could lead to command injection. An authenticated remote attacker with administrative privileges could exploit this vulnerability to execute arbitrary code on the system with system privileges.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-33721.
What is the affected software for vulnerability CVE-2021-33721?
The affected software for vulnerability CVE-2021-33721 is Siemens Sinec Network Management System (All versions < V1.0 SP2).
What is the severity of vulnerability CVE-2021-33721?
The severity of vulnerability CVE-2021-33721 is critical with a score of 7.2.
How does the vulnerability CVE-2021-33721 occur?
The vulnerability CVE-2021-33721 occurs due to incorrect neutralization of special elements when creating batch operations, which could lead to command injection.
How can an attacker exploit vulnerability CVE-2021-33721?
An authenticated remote attacker with administrative privileges could exploit vulnerability CVE-2021-33721.