CVE-2021-33735: SQL Injection
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-33735?
CVE-2021-33735 is a vulnerability found in SINEC NMS, allowing a privileged authenticated attacker to execute arbitrary commands in the local database.
What software versions are affected by CVE-2021-33735?
All versions of SINEC NMS prior to V1.0 SP2 Update 1 are affected by CVE-2021-33735.
What is the severity of CVE-2021-33735?
CVE-2021-33735 has a severity rating of 7.2 (high).
How can an attacker exploit CVE-2021-33735?
An attacker who is authenticated with privileges can exploit CVE-2021-33735 by sending crafted requests to the webserver of the affected SINEC NMS application, allowing them to execute arbitrary commands in the local database.
Where can I find more information about CVE-2021-33735?
You can find more information about CVE-2021-33735 in the Siemens ProductCERT advisory document available at the following link: [Siemens ProductCERT Advisory](https://cert-portal.siemens.com/productcert/pdf/ssa-163251.pdf)