CVE-2021-33722: Path Traversal
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system has a Path Traversal vulnerability when exporting a firmware container. With this a privileged authenticated attacker could create arbitrary files on an affected system.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-33722.
What is the affected software?
The affected software is Siemens SINEC NMS, all versions prior to V1.0 SP2 Update 1.
What is the severity of CVE-2021-33722?
CVE-2021-33722 has a severity level of 4.9, which is considered medium.
How does CVE-2021-33722 work?
CVE-2021-33722 exploits a path traversal vulnerability when exporting a firmware container in SINEC NMS, allowing a privileged authenticated attacker to create arbitrary files on the affected system.
How can I fix CVE-2021-33722?
To fix CVE-2021-33722, it is recommended to update the affected Siemens SINEC NMS software to V1.0 SP2 Update 1 or later, as specified in the Siemens security advisory.