cbcvebase.
CVE-2023-44315
published 2023-10-10

CVE-2023-44315: A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application improperly sanitizes certain SNMP configuration data retrieved…

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application improperly sanitizes certain SNMP configuration data retrieved from monitored devices. An attacker with access to a monitored device could prepare a stored cross-site scripting (XSS) attack that may lead to unintentional modification of application data by legitimate users.

Affected

2 ranges
VendorProductVersion rangeFixed in
siemenssinec_nms< V2.0V2.0
siemenssinec_nms< 2.02.0