Lucene search

K
nvd[email protected]NVD:CVE-2021-33732
HistoryOct 12, 2021 - 10:15 a.m.

CVE-2021-33732

2021-10-1210:15:12
CWE-89
web.nvd.nist.gov
5
vulnerability
sinec nms
privileged attacker
arbitrary commands
local database
crafted requests
webserver
affected application

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

52.5%

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.

Affected configurations

Nvd
Node
siemenssinec_nmsRange<1.0
OR
siemenssinec_nmsMatch1.0-
OR
siemenssinec_nmsMatch1.0sp1
OR
siemenssinec_nmsMatch1.0sp2
VendorProductVersionCPE
siemenssinec_nms*cpe:2.3:a:siemens:sinec_nms:*:*:*:*:*:*:*:*
siemenssinec_nms1.0cpe:2.3:a:siemens:sinec_nms:1.0:-:*:*:*:*:*:*
siemenssinec_nms1.0cpe:2.3:a:siemens:sinec_nms:1.0:sp1:*:*:*:*:*:*
siemenssinec_nms1.0cpe:2.3:a:siemens:sinec_nms:1.0:sp2:*:*:*:*:*:*

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

52.5%