CVE-2021-33727
published 2021-10-12CVE-2021-33727: A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could download the user profile of any user…
PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.82%
53.6th percentile
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could download the user profile of any user. With this, the attacker could leak confidential information of any user in the affected system.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | sinec_nms | < 1.0 | 1.0 |
| siemens | sinec_nms | — | — |
| siemens | sinec_nms | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5cj8-hj5v-h9wr: A vulnerability has been identified in SINEC NMS (All versions < V1
ghsa_unreviewed·2022-05-24
CVE-2021-33727 [MEDIUM] CWE-200 GHSA-5cj8-hj5v-h9wr: A vulnerability has been identified in SINEC NMS (All versions < V1
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could download the user profile of any user. With this, the attacker could leak confidential information of any user in the affected system.
CISA ICS
Siemens SINEC NMS
cisa_ics·2021-10-14·CVSS 4.9
[MEDIUM] Siemens SINEC NMS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC NMS
Last RevisedOctober 14, 2021
Alert CodeICSA-21-287-05
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS network management software
- Vulnerabilities: Improper Limitation of a Pathname to a Restricted Directory, Improper Authorization, Exposure of Sensitive Information to an Unauthorized Actor, Deserialization of Untrusted Data, Improper Neutralization of Special Elements used in an SQL Command
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could a
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-10-12
Published