CVE-2021-33733: SQL Injection
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-33733?
CVE-2021-33733 is a vulnerability in SINEC NMS (All versions < V1.0 SP2 Update 1) that allows a privileged authenticated attacker to execute arbitrary commands in the local database by sending crafted requests to the webserver.
How does CVE-2021-33733 affect Siemens SINEC NMS?
CVE-2021-33733 affects Siemens SINEC NMS versions prior to V1.0 SP2 Update 1.
What is the severity of CVE-2021-33733?
CVE-2021-33733 has a severity rating of 7.2 (High).
How can I fix CVE-2021-33733?
To fix CVE-2021-33733, users should update to version V1.0 SP2 Update 1 of Siemens SINEC NMS.
Where can I find more information about CVE-2021-33733?
More information about CVE-2021-33733 can be found in the Siemens ProductCERT advisory (SSA-163251) at the following URL: [https://cert-portal.siemens.com/productcert/pdf/ssa-163251.pdf](https://cert-portal.siemens.com/productcert/pdf/ssa-163251.pdf)