Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-25311

Опубликовано: 08 мар. 2022
Источник: nvd
CVSS3: 7.3
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). The affected software do not properly check privileges between users during the same web browser session, creating an unintended sphere of control. This could allow an authenticated low privileged user to achieve privilege escalation.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:siemens:sinec_network_management_system:*:*:*:*:*:*:*:*
Версия до 1.0.3 (исключая)
cpe:2.3:a:siemens:sinema_server:14.0:*:*:*:*:*:*:*

EPSS

Процентиль: 41%
0.0019
Низкий

7.3 High

CVSS3

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-269
NVD-CWE-Other

Связанные уязвимости

CVSS3: 7.2
github
почти 4 года назад

A vulnerability has been identified in SINEC NMS (All versions). The affected software do not properly check privileges between users during the same web browser session, creating an unintended sphere of control. This could allow an authenticated low privileged user to achieve privilege escalation.

EPSS

Процентиль: 41%
0.0019
Низкий

7.3 High

CVSS3

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-269
NVD-CWE-Other