CVE-2021-33724: Path Traversal
Published Oct 12, 2021
·Updated
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system contains an Arbitrary File Deletion vulnerability that possibly allows to delete an arbitrary file or directory under a user controlled path.
Affected Software
4 affected components
Siemens SINEC NMS<1.0
Siemens SINEC NMS=1.0
Siemens SINEC NMS=1.0-sp1
Siemens SINEC NMS=1.0-sp2
Remediation
Event History
Oct 12, 2021
CVE Published
via MITRE·09:49 AM
Data Sourced
via MITRE·09:49 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this SINEC NMS vulnerability?
The vulnerability ID for this SINEC NMS vulnerability is CVE-2021-33724.
2
What is the severity of CVE-2021-33724?
The severity of CVE-2021-33724 is critical (9.1).
3
Which versions of SINEC NMS are affected by CVE-2021-33724?
All versions of SINEC NMS up to V1.0 SP2 Update 1 are affected by CVE-2021-33724.
4
What is the impact of CVE-2021-33724?
CVE-2021-33724 allows an attacker to delete an arbitrary file or directory under a user controlled path.
5
How can I fix CVE-2021-33724?
To fix CVE-2021-33724, update SINEC NMS to V1.0 SP2 Update 1 or later.