CVE-2021-33725
published 2021-10-12CVE-2021-33725: A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to delete arbitrary files or directories under…
critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to delete arbitrary files or directories under a user controlled path and does not correctly check if the relative path is still within the intended target directory.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | sinec_nms | < 1.0 | 1.0 |
| siemens | sinec_nms | — | — |
| siemens | sinec_nms | — | — |