CVE-2021-33730: SQL Injection
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-33730?
The severity of CVE-2021-33730 is high with a severity value of 7.2.
How does CVE-2021-33730 affect Siemens SINEC NMS?
CVE-2021-33730 affects Siemens SINEC NMS versions < V1.0 SP2 Update 1.
What can a privileged authenticated attacker do with CVE-2021-33730?
A privileged authenticated attacker can execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.
Is there a fix for CVE-2021-33730?
Yes, upgrading to V1.0 SP2 Update 1 or later versions of Siemens SINEC NMS fixes the vulnerability.
Where can I find more information about CVE-2021-33730?
You can find more information about CVE-2021-33730 in the official Siemens ProductCERT advisory available at [PDF Link](https://cert-portal.siemens.com/productcert/pdf/ssa-163251.pdf).