Latest siemens sinec nms Vulnerabilities

A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application improperly sanitizes certain SNMP configuration data retrieved from monitored devices. An attacker with...
Siemens SINEC NMS<2.0
A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application assigns improper access rights to specific folders containing executable files and libraries. This c...
Siemens SINEC NMS<2.0
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from ...
redhat/logback-classic<1.2.9
redhat/candlepin<0:4.1.13-1.el7
redhat/candlepin<0:4.1.13-1.el8
Qos Logback<=1.2.7
Qos Logback=1.3.0-alpha0
Qos Logback=1.3.0-alpha1
and 14 more
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted reque...
Siemens SINEC NMS<1.0
Siemens SINEC NMS=1.0
Siemens SINEC NMS=1.0-sp1
Siemens SINEC NMS=1.0-sp2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted reque...
Siemens SINEC NMS<1.0
Siemens SINEC NMS=1.0
Siemens SINEC NMS=1.0-sp1
Siemens SINEC NMS=1.0-sp2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker that is able to import firmware containers to an affected system could execute arbitrary ...
Siemens SINEC NMS<1.0
Siemens SINEC NMS=1.0
Siemens SINEC NMS=1.0-sp1
Siemens SINEC NMS=1.0-sp2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted reque...
Siemens SINEC NMS<1.0
Siemens SINEC NMS=1.0
Siemens SINEC NMS=1.0-sp1
Siemens SINEC NMS=1.0-sp2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted reque...
Siemens SINEC NMS<1.0
Siemens SINEC NMS=1.0
Siemens SINEC NMS=1.0-sp1
Siemens SINEC NMS=1.0-sp2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to upload JSON objects that are deserialized to JAVA objects. Due to insecure deserializ...
Siemens SINEC NMS<1.0
Siemens SINEC NMS=1.0
Siemens SINEC NMS=1.0-sp1
Siemens SINEC NMS=1.0-sp2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted reque...
Siemens SINEC NMS<1.0
Siemens SINEC NMS=1.0
Siemens SINEC NMS=1.0-sp1
Siemens SINEC NMS=1.0-sp2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted reque...
Siemens SINEC NMS<1.0
Siemens SINEC NMS=1.0
Siemens SINEC NMS=1.0-sp1
Siemens SINEC NMS=1.0-sp2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted reque...
Siemens SINEC NMS<1.0
Siemens SINEC NMS=1.0
Siemens SINEC NMS=1.0-sp1
Siemens SINEC NMS=1.0-sp2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system has a Path Traversal vulnerability when exporting a firmware container. With this a privileged ...
Siemens SINEC NMS<1.0
Siemens SINEC NMS=1.0
Siemens SINEC NMS=1.0-sp1
Siemens SINEC NMS=1.0-sp2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to delete arbitrary files or directories under a user controlled path and does not corre...
Siemens SINEC NMS<1.0
Siemens SINEC NMS=1.0
Siemens SINEC NMS=1.0-sp1
Siemens SINEC NMS=1.0-sp2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to download arbitrary files under a user controlled path and does not correctly check if...
Siemens SINEC NMS<1.0
Siemens SINEC NMS=1.0
Siemens SINEC NMS=1.0-sp1
Siemens SINEC NMS=1.0-sp2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system contains an Arbitrary File Deletion vulnerability that possibly allows to delete an arbitrary f...
Siemens SINEC NMS<1.0
Siemens SINEC NMS=1.0
Siemens SINEC NMS=1.0-sp1
Siemens SINEC NMS=1.0-sp2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could download the user profile of any user. With this, the attacker could leak confident...
Siemens SINEC NMS<1.0
Siemens SINEC NMS=1.0
Siemens SINEC NMS=1.0-sp1
Siemens SINEC NMS=1.0-sp2
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affec...
Apache HTTP server<=2.4.48
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
and 16 more
Apache HTTP Server-Side Request Forgery (SSRF)
Apache HTTP server<=2.4.48
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Debian Debian Linux=9.0
Debian Debian Linux=10.0
and 27 more
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
redhat/jbcs-httpd24-apr<0:1.6.3-107.el8
redhat/jbcs-httpd24-apr-util<0:1.6.1-84.el8
redhat/jbcs-httpd24-curl<0:7.78.0-2.el8
redhat/jbcs-httpd24-httpd<0:2.4.37-78.el8
redhat/jbcs-httpd24-nghttp2<0:1.39.2-39.el8
redhat/jbcs-httpd24-openssl<1:1.1.1g-8.el8
and 38 more
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it...
rust/openssl-src<111.15.0
debian/openssl
IBM Cognos Analytics<=12.0.0-12.0.1
IBM Cognos Analytics<=11.2.0-11.2.4 FP2
IBM Cognos Analytics<=11.1.1-11.1.7 FP7
OpenSSL OpenSSL>=1.1.1<1.1.1k
and 202 more
Siemens SINEC NMS FirmwareFileUtils extractToFolder Directory Traversal Remote Code Execution Vulnerability
Siemens Sinec Network Management System<1.0
Siemens Sinec Network Management System=1.0
Siemens Sinec Network Management System=1.0-sp1
Siemens SINEMA Server<14.0
Siemens SINEMA Server=14.0
Siemens SINEMA Server=14.0-sp1
and 3 more

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203