Stored Cross-Site Scripting Vulnerability in SINEC NMS by Siemens
CVE-2023-44315

5.4MEDIUM

Key Information:

Vendor
Siemens
Status
Vendor
CVE Published:
10 October 2023

Summary

A stored cross-site scripting vulnerability exists in SINEC NMS prior to version 2.0. This flaw arises from inadequate sanitization of SNMP configuration data sourced from monitored devices. An attacker exploiting this vulnerability could implement a stored XSS attack, leading to potential unauthorized alterations of application data by authenticated users, undermining the integrity of the network management system.

Affected Version(s)

SINEC NMS All versions < V2.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.