This could allow an authenticated medium-privileged attacker to write arbitrary content to any location in the filesystem of the host system.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-42695 | A vulnerability has been identified in SINEC NMS (All versions < V3.0 SP1). The affected application contains a database function, that does not properly restrict the permissions of users to write to the filesystem of the host system. This could allow an authenticated medium-privileged attacker to write arbitrary content to any location in the filesystem of the host system. |
Wed, 13 Nov 2024 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:siemens:sinec_nms:3.0:-:*:*:*:*:*:* |
Tue, 12 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens sinec Nms |
|
| CPEs | cpe:2.3:a:siemens:sinec_nms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Siemens
Siemens sinec Nms |
|
| Metrics |
ssvc
|
Tue, 12 Nov 2024 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in SINEC NMS (All versions < V3.0 SP1). The affected application contains a database function, that does not properly restrict the permissions of users to write to the filesystem of the host system. This could allow an authenticated medium-privileged attacker to write arbitrary content to any location in the filesystem of the host system. | |
| Weaknesses | CWE-732 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2024-11-12T16:25:18.148Z
Reserved: 2024-10-02T12:40:26.553Z
Link: CVE-2024-47808
Updated: 2024-11-12T16:25:13.481Z
Status : Analyzed
Published: 2024-11-12T13:15:10.677
Modified: 2024-11-13T23:14:07.650
Link: CVE-2024-47808
No data.
OpenCVE Enrichment
No data.
EUVD