A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to delete arbitrary files or directories under a user controlled path and does not correctly check if the relative path is still within the intended target directory.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HSiemens Sinec Nms
APPSiemens1.0< 1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
Related vulnerabilities
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
CVE-2025-40736CRITICAL9.3PL ✓same product
Siemens SINEC NMS — Auth Bypass umożliwiający reset hasła superadmina
CVE-2024-41940CRITICAL9.4PL ✓same product
Siemens SINEC NMS — wykonanie poleceń OS z podwyższonymi uprawnieniami
CVE-2021-33724CRITICAL9.1PL ✓same product
Siemens SINEC NMS — usunięcie dowolnego pliku przez path traversal
CVE-2021-39275CRITICAL9.8PL ✓same product
Apache HTTP Server — buffer overflow w funkcji ap_escape_quotes()