Stored Cross-Site Scripting Vulnerability in SINEC NMS by Siemens
CVE-2023-44315
4.7MEDIUM
Summary
A stored cross-site scripting vulnerability exists in SINEC NMS prior to version 2.0. This flaw arises from inadequate sanitization of SNMP configuration data sourced from monitored devices. An attacker exploiting this vulnerability could implement a stored XSS attack, leading to potential unauthorized alterations of application data by authenticated users, undermining the integrity of the network management system.
Affected Version(s)
SINEC NMS 0
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved