Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-23811


A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application allows users to upload arbitrary files via TFTP. This could allow an attacker to upload malicious firmware images or other files, that could potentially lead to remote code execution.


Published

2024-02-13T09:15:49.760

Last Modified

2024-11-21T08:58:28.397

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-434

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application siemens sinec_nms < 2.0 Yes
Application siemens sinec_nms 2.0 Yes

References