CVE-2024-23810: SQL Injection
Published Feb 13, 2024
·Updated
A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application is vulnerable to SQL injection. This could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the server database.
Affected Software
2 affected components
Siemens SINEC NMS<2.0
Siemens SINEC NMS=2.0
Event History
Feb 13, 2024
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23810?
CVE-2024-23810 is considered a critical vulnerability due to its potential for unauthorized SQL query execution.
2
How do I fix CVE-2024-23810?
To mitigate CVE-2024-23810, upgrade Siemens SINEC NMS to at least version 2.0 SP1.
3
What types of attacks can exploit CVE-2024-23810?
CVE-2024-23810 can be exploited by unauthenticated remote attackers executing arbitrary SQL queries.
4
Which versions of Siemens SINEC NMS are affected by CVE-2024-23810?
All versions of Siemens SINEC NMS prior to 2.0 SP1 are affected by CVE-2024-23810.
5
Is user authentication required to exploit CVE-2024-23810?
No, CVE-2024-23810 can be exploited by attackers without authentication.