Stored Cross-Site Scripting Vulnerability in SINEC NMS by Siemens
CVE-2023-44315

4.7MEDIUM

Key Information:

Vendor
Siemens
Status
Vendor
CVE Published:
10 October 2023

Summary

A stored cross-site scripting vulnerability exists in SINEC NMS prior to version 2.0. This flaw arises from inadequate sanitization of SNMP configuration data sourced from monitored devices. An attacker exploiting this vulnerability could implement a stored XSS attack, leading to potential unauthorized alterations of application data by authenticated users, undermining the integrity of the network management system.

Affected Version(s)

SINEC NMS 0

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.