CVE-2021-37201
14.09.2021, 11:15
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1). The web interface of affected devices is vulnerable to a Cross-Site Request Forgery (CSRF) attack. This could allow an attacker to manipulate the SINEC NMS configuration by tricking an unsuspecting user with administrative privileges to click on a malicious link.
Vendor | Product | Version |
---|---|---|
siemens | sinec_network_management_system | 𝑥 < 1.0 |
siemens | sinec_network_management_system | 1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration