cbcvebase.
CVE-2021-37200
published 2021-09-14

CVE-2021-37200: A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1). An attacker with access to the webserver of an affected system could download…

PriorityP263high7.7CVSS 3.1
AVNACLPRLUINSCCHINAN
EPSS
37.38%
98.4th percentile
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1). An attacker with access to the webserver of an affected system could download arbitrary files from the underlying filesystem by sending a specially crafted HTTP request.

Affected

3 ranges
VendorProductVersion rangeFixed in
siemenssinec_network_management_system< 1.01.0
siemenssinec_network_management_system
siemenssinec_nms

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2021-37200 is a path traversal (CWE-22) vulnerability in SINEC NMS web server; detect specially crafted HTTP requests attempting directory traversal to download arbitrary files from the underlying filesystem.
  • The vulnerability is exploitable remotely with low attack complexity and requires only low privileges (CVSS: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N); monitor SINEC NMS web interface for authenticated low-privilege users making unusual file download requests.
  • ·All versions of SINEC NMS prior to v1.0 SP1 are affected; the vulnerability is remediated in v1.0 SP1 and later.
  • ·No known public exploits specifically target this vulnerability at time of advisory publication.

CVSS provenance

nvdv3.17.7HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.