First published: Tue Feb 13 2024(Updated: )
A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application incorrectly neutralizes special elements when creating a report which could lead to command injection.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SINEC NMS SP1 Update 1 | <2.0 | |
Siemens SINEC NMS SP1 Update 1 | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23812 is classified as a high severity vulnerability due to its potential for command injection.
To fix CVE-2024-23812, upgrade SINEC NMS to version 2.0 SP1 or later.
The potential impact of CVE-2024-23812 includes unauthorized command execution on the affected system.
CVE-2024-23812 affects all versions of SINEC NMS prior to version 2.0 SP1.
There are no known workarounds for CVE-2024-23812; upgrading to a secure version is recommended.