Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pjpw-9hx5-m28p

Опубликовано: 12 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 8.3
CVSS3: 8.4

Описание

A vulnerability has been identified in SINEC NMS (All versions < V3.0 SP1). The affected application contains a database function, that does not properly restrict the permissions of users to write to the filesystem of the host system. This could allow an authenticated medium-privileged attacker to write arbitrary content to any location in the filesystem of the host system.

A vulnerability has been identified in SINEC NMS (All versions < V3.0 SP1). The affected application contains a database function, that does not properly restrict the permissions of users to write to the filesystem of the host system. This could allow an authenticated medium-privileged attacker to write arbitrary content to any location in the filesystem of the host system.

EPSS

Процентиль: 24%
0.00081
Низкий

8.3 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 8.4
nvd
около 1 года назад

A vulnerability has been identified in SINEC NMS (All versions < V3.0 SP1). The affected application contains a database function, that does not properly restrict the permissions of users to write to the filesystem of the host system. This could allow an authenticated medium-privileged attacker to write arbitrary content to any location in the filesystem of the host system.

CVSS3: 8.4
fstec
около 1 года назад

Уязвимость системы сетевого управления для мониторинга промышленными сетями Siemens SINEC NMS, связанная с неправильным присвоением разрешений для критичного ресурса, позволяющая нарушителю записывать произвольные данные в произвольное место файловой системы хоста

EPSS

Процентиль: 24%
0.00081
Низкий

8.3 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-732