CVE Vulnerabilities

CVE-2021-33723

Published: Oct 12, 2021 | Modified: Oct 27, 2022
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could change the user profile of any user without proper authorization. With this, the attacker could change the password of any user in the affected system.

Affected Software

Name Vendor Start Version End Version
Sinec_nms Siemens * 1.0 (excluding)
Sinec_nms Siemens 1.0 (including) 1.0 (including)
Sinec_nms Siemens 1.0-sp1 (including) 1.0-sp1 (including)
Sinec_nms Siemens 1.0-sp2 (including) 1.0-sp2 (including)

References