First published: Tue Sep 14 2021(Updated: )
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1). The web interface of affected devices is vulnerable to a Cross-Site Request Forgery (CSRF) attack. This could allow an attacker to manipulate the SINEC NMS configuration by tricking an unsuspecting user with administrative privileges to click on a malicious link.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Sinec Network Management System | <1.0 | |
Siemens Sinec Network Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37201 is a vulnerability in SINEC NMS (All versions < V1.0 SP1) that allows an attacker to perform a Cross-Site Request Forgery (CSRF) attack and manipulate the SINEC NMS configuration.
CVE-2021-37201 has a severity rating of 8.8 (high).
CVE-2021-37201 affects Siemens Sinec Network Management System versions up to and including 1.0 SP1.
An attacker can exploit CVE-2021-37201 by tricking an unsuspecting user with administrative privileges into performing certain actions on the SINEC NMS web interface.
Siemens has released a security advisory with mitigation measures to address the vulnerability. Please refer to the official Siemens security advisory for detailed instructions.