Lucene search

K
cvelistSiemensCVELIST:CVE-2021-33721
HistoryAug 10, 2021 - 10:35 a.m.

CVE-2021-33721

2021-08-1010:35:32
CWE-78
siemens
www.cve.org
3
vulnerability
sinec nms
command injection
administrative privileges

AI Score

7.6

Confidence

High

EPSS

0.002

Percentile

55.2%

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2). The affected application incorrectly neutralizes special elements when creating batch operations which could lead to command injection. An authenticated remote attacker with administrative privileges could exploit this vulnerability to execute arbitrary code on the system with system privileges.

CNA Affected

[
  {
    "product": "SINEC NMS",
    "vendor": "Siemens",
    "versions": [
      {
        "status": "affected",
        "version": "All versions < V1.0 SP2"
      }
    ]
  }
]

AI Score

7.6

Confidence

High

EPSS

0.002

Percentile

55.2%

Related for CVELIST:CVE-2021-33721