CVE-2021-33725: Path Traversal
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to delete arbitrary files or directories under a user controlled path and does not correctly check if the relative path is still within the intended target directory.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-33725?
CVE-2021-33725 is a vulnerability identified in SINEC NMS (All versions < V1.0 SP2 Update 1) that allows an attacker to delete arbitrary files or directories under a user-controlled path without proper validation.
How severe is CVE-2021-33725?
CVE-2021-33725 has a severity rating of 9.1 (critical).
Which software versions are affected by CVE-2021-33725?
CVE-2021-33725 affects all versions of SINEC NMS prior to V1.0 SP2 Update 1.
How can an attacker exploit CVE-2021-33725?
An attacker can exploit CVE-2021-33725 by manipulating a user-controlled path to delete arbitrary files or directories on the affected system.
Is there a fix for CVE-2021-33725?
Yes, the fix for CVE-2021-33725 is to update to version V1.0 SP2 Update 1 of SINEC NMS.