A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application exposes an endpoint that allows an unauthorized modification of administrative credentials. This could allow an unauthenticated attacker to reset the superadmin password and gain full control of the application (ZDI-CAN-26569).
The application exposes a network endpoint that does not require any authentication before processing a request to modify login credentials (CWE-306: missing authentication for critical function). An attacker can send a properly crafted request to this endpoint and reset the superadmin account password. After changing the password, the attacker gains full administrative access to the SINEC NMS system.
An unauthenticated remote attacker can gain full control over the SINEC NMS application by resetting the superadmin account password, which opens the path to managing the entire network infrastructure supervised by the system.
Siemens SINEC NMS must be updated to version V4.0 or newer. Detailed information regarding the patch is available in the Siemens security bulletin: https://cert-portal.siemens.com/productcert/html/ssa-078892.html. Until the update is applied, it is recommended to restrict network access to the SINEC NMS management interface exclusively to trusted hosts.
Siemens SINEC NMS — all versions below V4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSiemens Sinec Nms
APPSiemens< 4.0
Related vulnerabilities
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
Siemens SINEC NMS — wykonanie poleceń OS z podwyższonymi uprawnieniami
Siemens SINEC NMS — usunięcie dowolnego pliku przez path traversal
Path Traversal w Siemens SINEC NMS — usuwanie dowolnych plików
Apache HTTP Server — buffer overflow w funkcji ap_escape_quotes()