CVE-2021-33725
12.10.2021, 10:15
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to delete arbitrary files or directories under a user controlled path and does not correctly check if the relative path is still within the intended target directory.
| Vendor | Product | Version |
|---|---|---|
| siemens | sinec_nms | 𝑥 < 1.0 |
| siemens | sinec_nms | 1.0 |
| siemens | sinec_nms | 1.0:sp1 |
| siemens | sinec_nms | 1.0:sp2 |
𝑥
= Vulnerable software versions