A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly validate user input to a privileged command queue. This could allow an authenticated attacker to execute OS commands with elevated privileges.
The SINEC NMS application does not perform proper validation of user-supplied input data passed to an internal, privileged command queue. An attacker with access to an application account can pass crafted input data, which will be processed by this queue and executed as operating system commands with elevated privileges. The vulnerability is classified as CWE-20 (Improper Input Validation).
An authenticated attacker can execute arbitrary operating system commands with elevated privileges, which may lead to complete system takeover, data modification, service availability disruption, and information confidentiality breach in both the local system and related systems.
Siemens SINEC NMS must be updated to version V3.0 or later. Detailed information and patches are available in the Siemens ProductCERT security bulletin: https://cert-portal.siemens.com/productcert/html/ssa-784301.html
Siemens SINEC NMS — all versions below V3.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSiemens Sinec Nms
APPSiemens< 3.0
Related vulnerabilities
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
Siemens SINEC NMS — Auth Bypass umożliwiający reset hasła superadmina
Siemens SINEC NMS — usunięcie dowolnego pliku przez path traversal
Path Traversal w Siemens SINEC NMS — usuwanie dowolnych plików
Apache HTTP Server — buffer overflow w funkcji ap_escape_quotes()