First published: Tue Aug 10 2021(Updated: )
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2). The affected application incorrectly neutralizes special elements when creating batch operations which could lead to command injection. An authenticated remote attacker with administrative privileges could exploit this vulnerability to execute arbitrary code on the system with system privileges.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Sinec Network Management System | <1.0 | |
Siemens Sinec Network Management System | =1.0 | |
Siemens Sinec Network Management System | =1.0-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-33721.
The affected software for vulnerability CVE-2021-33721 is Siemens Sinec Network Management System (All versions < V1.0 SP2).
The severity of vulnerability CVE-2021-33721 is critical with a score of 7.2.
The vulnerability CVE-2021-33721 occurs due to incorrect neutralization of special elements when creating batch operations, which could lead to command injection.
An authenticated remote attacker with administrative privileges could exploit vulnerability CVE-2021-33721.