SINEC NMS Vulnerability: Authenticated Data Export Leads to File System Access
CVE-2024-31978
What is CVE-2024-31978?
A vulnerability has been identified in the SINEC NMS platform from Siemens that affects all versions prior to V2.0 SP2. This vulnerability is linked to the API endpoint that allows authenticated users to export monitoring data. The API is susceptible to path traversal attacks, which could permit an authenticated attacker to access and download sensitive files from the system's file directory. In certain scenarios, the exploited files may be deleted from the file system after being downloaded, potentially leading to data loss and unauthorized information retrieval.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SINEC NMS 0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved