CVE-2023-44315: XSS
A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application improperly sanitizes certain SNMP configuration data retrieved from monitored devices. An attacker with access to a monitored device could prepare a stored cross-site scripting (XSS) attack that may lead to unintentional modification of application data by legitimate users.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-44315.
What is the affected software?
The affected software is Siemens Sinec Nms, all versions prior to V2.0.
What is the severity rating of CVE-2023-44315?
The severity rating of CVE-2023-44315 is medium, with a CVSS score of 5.4.
What is the CWE ID of CVE-2023-44315?
The CWE ID of CVE-2023-44315 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
How can I fix the vulnerability in Siemens Sinec Nms?
To fix the vulnerability in Siemens Sinec Nms, update the software to version 2.0 or later.