First published: Tue Oct 12 2021(Updated: )
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SINEC NMS | <1.0 | |
Siemens SINEC NMS | =1.0 | |
Siemens SINEC NMS | =1.0-sp1 | |
Siemens SINEC NMS | =1.0-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33735 is a vulnerability found in SINEC NMS, allowing a privileged authenticated attacker to execute arbitrary commands in the local database.
All versions of SINEC NMS prior to V1.0 SP2 Update 1 are affected by CVE-2021-33735.
CVE-2021-33735 has a severity rating of 7.2 (high).
An attacker who is authenticated with privileges can exploit CVE-2021-33735 by sending crafted requests to the webserver of the affected SINEC NMS application, allowing them to execute arbitrary commands in the local database.
You can find more information about CVE-2021-33735 in the Siemens ProductCERT advisory document available at the following link: [Siemens ProductCERT Advisory](https://cert-portal.siemens.com/productcert/pdf/ssa-163251.pdf)