First published: Tue Feb 13 2024(Updated: )
A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application is vulnerable to SQL injection. This could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the server database.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SINEC NMS | <2.0 | |
Siemens SINEC NMS | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23810 is considered a critical vulnerability due to its potential for unauthorized SQL query execution.
To mitigate CVE-2024-23810, upgrade Siemens SINEC NMS to at least version 2.0 SP1.
CVE-2024-23810 can be exploited by unauthenticated remote attackers executing arbitrary SQL queries.
All versions of Siemens SINEC NMS prior to 2.0 SP1 are affected by CVE-2024-23810.
No, CVE-2024-23810 can be exploited by attackers without authentication.