CVE-2021-33729: SQL Injection
Published Oct 12, 2021
·Updated
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker that is able to import firmware containers to an affected system could execute arbitrary commands in the local database.
Affected Software
4 affected components
Siemens SINEC NMS<1.0
Siemens SINEC NMS=1.0
Siemens SINEC NMS=1.0-sp1
Siemens SINEC NMS=1.0-sp2
Remediation
Event History
Oct 12, 2021
CVE Published
via MITRE·09:49 AM
Data Sourced
via MITRE·09:49 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-33729?
CVE-2021-33729 is a vulnerability identified in SINEC NMS (All versions < V1.0 SP2 Update 1) that allows an authenticated attacker to execute arbitrary commands in the local database.
2
How severe is CVE-2021-33729?
CVE-2021-33729 has a severity rating of 8.8, which is considered high.
3
Which software versions are affected by CVE-2021-33729?
All versions of SINEC NMS less than V1.0 SP2 Update 1 are affected.
4
How can an attacker exploit CVE-2021-33729?
An authenticated attacker can exploit CVE-2021-33729 by importing firmware containers to the affected system.
5
Is there a fix available for CVE-2021-33729?
Yes, updating to version V1.0 SP2 Update 1 or later resolves the vulnerability.