Description
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could download the user profile of any user. With this, the attacker could leak confidential information of any user in the affected system.
Related CPE's
a
siemens
sinec_nms
4
References
https://cert-portal.siemens.com/productcert/pdf/ssa-163251.pdf
PatchVendor Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-163251.pdf
PatchVendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
6.5 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2021-10-12T08:15:11.960Z
4 years agoLast modified
2024-11-21T05:09:27.517Z
1 year ago