Securing Network Management Systems (Part 3): Siemens SINEC NMS
ID: 5a8dc95e-d102-5204-9e7a-978411f556e6
STIX ID: report--5a8dc95e-d102-5204-9e7a-978411f556e6
Feed Name: Claroty Team82
Threat Score
Team82 disclosed 15 vulnerabilities in Siemens SINEC NMS, demonstrating an exploit chain that first allows an authenticated user to takeover an administrator account (CVE-2021-33723) and then leverage a path-traversal file-write during container export (CVE-2021-33722) to drop a JSP webshell and achieve remote code execution as NT AUTHORITY\SYSTEM; Siemens issued an advisory and fixed the flaws in V1.0 SP2 Update 1 and later.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
