CVE-2023-44315
10.10.2023, 11:15
A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application improperly sanitizes certain SNMP configuration data retrieved from monitored devices. An attacker with access to a monitored device could prepare a stored cross-site scripting (XSS) attack that may lead to unintentional modification of application data by legitimate users.
Vendor | Product | Version |
---|---|---|
siemens | sinec_nms | 𝑥 < 2.0 |
𝑥
= Vulnerable software versions