Siemens Sinec Nms vulnerabilities
61 known vulnerabilities affecting siemens/sinec_nms.
Total CVEs
61
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL8HIGH41MEDIUM11LOW1
Vulnerabilities
Page 3 of 4
CVE-2021-33736P3HIGHCVSS 7.2fixed in 1.0v1.0+1 more2021-10-12
CVE-2021-33736 [HIGH] CWE-89 CVE-2021-33736: A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged au
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.
nvd
CVE-2021-33726P3HIGHCVSS 7.5fixed in 1.0v1.0+1 more2021-10-12
CVE-2021-33726 [HIGH] CWE-22 CVE-2021-33726: A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected sy
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to download arbitrary files under a user controlled path and does not correctly check if the relative path is still within the intended target directory.
nvd
CVE-2021-33735P3HIGHCVSS 7.2fixed in 1.0v1.0+1 more2021-10-12
CVE-2021-33735 [HIGH] CWE-89 CVE-2021-33735: A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged au
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.
nvd
CVE-2021-37201P3HIGHCVSS 8.8vAll versions < V1.0 SP12021-09-14
CVE-2021-37201 [HIGH] CWE-352 CVE-2021-37201: A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1). The web interface of aff
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1). The web interface of affected devices is vulnerable to a Cross-Site Request Forgery (CSRF) attack. This could allow an attacker to manipulate the SINEC NMS configuration by tricking an unsuspecting user with administrative privileges to click on a malicious link.
nvd
CVE-2023-46285P3HIGHCVSS 7.5fixed in V2.0 SP12023-12-12
CVE-2023-46285 [HIGH] CWE-20 CVE-2023-46285: A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcente
A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), To
nvd
CVE-2023-46284P3HIGHCVSS 7.5fixed in V2.0 SP12023-12-12
CVE-2023-46284 [HIGH] CWE-120 CVE-2023-46284: A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcente
A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), T
nvd
CVE-2023-46283P3HIGHCVSS 7.5fixed in V2.0 SP12023-12-12
CVE-2023-46283 [HIGH] CWE-120 CVE-2023-46283: A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcente
A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), T
nvd
CVE-2021-42550P3MEDIUMCVSS 6.6fixed in 1.0.32021-12-16
CVE-2021-42550 [MEDIUM] CWE-502 CVE-2021-42550: In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit config
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
nvd
CVE-2024-36398P3HIGHCVSS 7.8fixed in 3.0fixed in V3.02024-08-13
CVE-2024-36398 [HIGH] CWE-250 CVE-2024-36398: A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application exe
A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application executes a subset of its services as `NT AUTHORITY\SYSTEM`. This could allow a local attacker to execute operating system commands with elevated privileges.
nvd
CVE-2022-30527P3HIGHCVSS 7.8fixed in 2.0fixed in V2.02023-10-10
CVE-2022-30527 [HIGH] CWE-732 CVE-2022-30527: A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application ass
A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application assigns improper access rights to specific folders containing executable files and libraries.
This could allow an authenticated local attacker to inject arbitrary code and escalate privileges.
nvd
CVE-2025-30033P3HIGHCVSS 7.8fixed in V4.02025-08-12
CVE-2025-30033 [HIGH] CWE-427 CVE-2025-30033: The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute
The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup component.
nvd
CVE-2021-33723P3MEDIUMCVSS 6.5fixed in 1.0v1.0+1 more2021-10-12
CVE-2021-33723 [MEDIUM] CWE-285 CVE-2021-33723: A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticate
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could change the user profile of any user without proper authorization. With this, the attacker could change the password of any user in the affected system.
nvd
CVE-2021-33727P4MEDIUMCVSS 6.5fixed in 1.0v1.0+1 more2021-10-12
CVE-2021-33727 [MEDIUM] CWE-200 CVE-2021-33727: A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticate
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could download the user profile of any user. With this, the attacker could leak confidential information of any user in the affected system.
nvd
CVE-2024-47808P4MEDIUMCVSS 6.5fixed in 3.0v3.0+1 more2024-11-12
CVE-2024-47808 [MEDIUM] CWE-732 CVE-2024-47808: A vulnerability has been identified in SINEC NMS (All versions < V3.0 SP1). The affected application
A vulnerability has been identified in SINEC NMS (All versions < V3.0 SP1). The affected application contains a database function, that does not properly restrict the permissions of users to write to the filesystem of the host system.
This could allow an authenticated medium-privileged attacker to write arbitrary content to any location in the files
nvd
CVE-2020-7580P4MEDIUMCVSS 6.7vAll versions < V1.0 SP22020-06-10
CVE-2020-7580 [MEDIUM] CWE-428 CVE-2020-7580: A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET
A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Upd3), SIMATIC PCS neo (All versions < V3.0 SP1), SIMATIC ProSave (All versions < V17), SIMATIC S7-1500 Softwa
nvd
CVE-2021-33722P4MEDIUMCVSS 4.9fixed in 1.0v1.0+1 more2021-10-12
CVE-2021-33722 [MEDIUM] CWE-22 CVE-2021-33722: A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected sy
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system has a Path Traversal vulnerability when exporting a firmware container. With this a privileged authenticated attacker could create arbitrary files on an affected system.
nvd
CVE-2023-46280P4MEDIUMCVSS 6.5fixed in V3.0fixed in V3.0 SP12024-05-14
CVE-2023-46280 [MEDIUM] CWE-125 CVE-2023-46280: A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Aut
A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 Upd5), SIMATIC NET PC Software V16 (All versions < V16 Update 8), SIMATIC NET PC Software V17 (All versions), SIMATIC NET PC Software V18 (All versions < V18 SP1), SIM
nvd
CVE-2023-46282P4MEDIUMCVSS 6.1fixed in V2.0 SP12023-12-12
CVE-2023-46282 [MEDIUM] CWE-79 CVE-2023-46282: A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcente
A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions),
nvd
CVE-2023-44315P4MEDIUMCVSS 5.4fixed in 2.0fixed in V2.02023-10-10
CVE-2023-44315 [MEDIUM] CWE-79 CVE-2023-44315: A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application imp
A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application improperly sanitizes certain SNMP configuration data retrieved from monitored devices. An attacker with access to a monitored device could prepare a stored cross-site scripting (XSS) attack that may lead to unintentional modification of application data b
nvd
CVE-2024-41941P4MEDIUMCVSS 4.3fixed in 3.0fixed in V3.02024-08-13
CVE-2024-41941 [MEDIUM] CWE-863 CVE-2024-41941: A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application doe
A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This could allow an authenticated attacker to bypass the checks and modify settings in the application without authorization.
nvd