CRITICAL🇵🇱 Wersja polska

CVE-2024-41940

CVSS 9.4v4.0pub. 2024-08-13upd. 2024-08-14

A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly validate user input to a privileged command queue. This could allow an authenticated attacker to execute OS commands with elevated privileges.

🤖 AI Analysis
How it works

The SINEC NMS application does not perform proper validation of user-supplied input data passed to an internal, privileged command queue. An attacker with access to an application account can pass crafted input data, which will be processed by this queue and executed as operating system commands with elevated privileges. The vulnerability is classified as CWE-20 (Improper Input Validation).

Impact

An authenticated attacker can execute arbitrary operating system commands with elevated privileges, which may lead to complete system takeover, data modification, service availability disruption, and information confidentiality breach in both the local system and related systems.

Mitigation & patch

Siemens SINEC NMS must be updated to version V3.0 or later. Detailed information and patches are available in the Siemens ProductCERT security bulletin: https://cert-portal.siemens.com/productcert/html/ssa-784301.html

Who is affected

Siemens SINEC NMS — all versions below V3.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Siemens Sinec Nms

    APP
    Siemens
    < 3.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product

SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego

CVE-2025-40736CRITICAL9.3PL ✓same product

Siemens SINEC NMS — Auth Bypass umożliwiający reset hasła superadmina

CVE-2021-33724CRITICAL9.1PL ✓same product

Siemens SINEC NMS — usunięcie dowolnego pliku przez path traversal

CVE-2021-33725CRITICAL9.1PL ✓same product

Path Traversal w Siemens SINEC NMS — usuwanie dowolnych plików

CVE-2021-39275CRITICAL9.8PL ✓same product

Apache HTTP Server — buffer overflow w funkcji ap_escape_quotes()