A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). The affected software do not properly check privileges between users during the same web browser session, creating an unintended sphere of control. This could allow an authenticated low privileged user to achieve privilege escalation.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HSiemens Sinec Network Management System
APPSiemens< 1.0.3Siemens Sinema Server
APPSiemens14.0
Related vulnerabilities
Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
Apache HTTP Server — buffer overflow w funkcji ap_escape_quotes()
Siemens SINEMA Server — błędna walidacja sesji umożliwia privilege escalation
A vulnerability has been identified in SINEMA Server V14 (All versions). The affected application improperly s...