CRITICAL🇵🇱 Wersja polska

CVE-2021-33725

CVSS 9.1v3.1pub. 2021-10-12upd. 2024-11-21

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to delete arbitrary files or directories under a user controlled path and does not correctly check if the relative path is still within the intended target directory.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Siemens Sinec Nms

    APP
    Siemens
    1.0< 1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product

SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego

CVE-2025-40736CRITICAL9.3PL ✓same product

Siemens SINEC NMS — Auth Bypass umożliwiający reset hasła superadmina

CVE-2024-41940CRITICAL9.4PL ✓same product

Siemens SINEC NMS — wykonanie poleceń OS z podwyższonymi uprawnieniami

CVE-2021-33724CRITICAL9.1PL ✓same product

Siemens SINEC NMS — usunięcie dowolnego pliku przez path traversal

CVE-2021-39275CRITICAL9.8PL ✓same product

Apache HTTP Server — buffer overflow w funkcji ap_escape_quotes()