Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-44315


A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application improperly sanitizes certain SNMP configuration data retrieved from monitored devices. An attacker with access to a monitored device could prepare a stored cross-site scripting (XSS) attack that may lead to unintentional modification of application data by legitimate users.


Published

2023-10-10T11:15:12.993

Last Modified

2024-11-21T08:25:39.047

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.7 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application siemens sinec_nms < 2.0 Yes

References