Siemens SINEC NMS
cpe:2.3:a:siemens:sinec_network_management_system:*:*:*:*:*:*:*, +2 more
- < V4.0
A path traversal vulnerability has been identified in Siemens SINEC NMS, affecting all versions prior to 4.0. The issue arises because the application fails to properly validate file paths when extracting uploaded ZIP files. This flaw could enable an attacker to write arbitrary files to restricted locations and potentially execute code with elevated privileges.
Exploitation of this vulnerability could lead to unauthorized file writes in restricted directories and allow for execution of arbitrary code with elevated privileges.
Users are advised to update to SINEC NMS version 4.0 or later. For guidance on updating, please refer to the Siemens support page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.