A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1). An attacker with access to the webserver of an affected system could download arbitrary files from the underlying filesystem by sending a specially crafted HTTP request.
2021-09-14T11:15:26.240
2024-11-21T06:14:50.877
Modified
CVSSv3.1: 7.7 (HIGH)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | siemens | sinec_network_management_system | < 1.0 | Yes |
Application | siemens | sinec_network_management_system | 1.0 | Yes |