SINEC NMS Vulnerability: Authenticated Data Export Leads to File System Access
CVE-2024-31978

7.6HIGH

Key Information:

Vendor
Siemens
Status
Vendor
CVE Published:
9 April 2024

Summary

A vulnerability has been identified in the SINEC NMS platform from Siemens that affects all versions prior to V2.0 SP2. This vulnerability is linked to the API endpoint that allows authenticated users to export monitoring data. The API is susceptible to path traversal attacks, which could permit an authenticated attacker to access and download sensitive files from the system's file directory. In certain scenarios, the exploited files may be deleted from the file system after being downloaded, potentially leading to data loss and unauthorized information retrieval.

Affected Version(s)

SINEC NMS 0

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.