Show filters
36 Total Results
Displaying 21-30 of 36
Sort by:
Attacker Value
Unknown
CVE-2021-33730
Disclosure Date: October 12, 2021 (last updated November 28, 2024)
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.
0
Attacker Value
Unknown
CVE-2021-33727
Disclosure Date: October 12, 2021 (last updated November 28, 2024)
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could download the user profile of any user. With this, the attacker could leak confidential information of any user in the affected system.
0
Attacker Value
Unknown
CVE-2021-33734
Disclosure Date: October 12, 2021 (last updated November 28, 2024)
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.
0
Attacker Value
Unknown
CVE-2021-33733
Disclosure Date: October 12, 2021 (last updated November 28, 2024)
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.
0
Attacker Value
Unknown
CVE-2021-33735
Disclosure Date: October 12, 2021 (last updated November 28, 2024)
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.
0
Attacker Value
Unknown
CVE-2021-33728
Disclosure Date: October 12, 2021 (last updated November 28, 2024)
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to upload JSON objects that are deserialized to JAVA objects. Due to insecure deserialization of user-supplied content by the affected software, a privileged attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary code on the device with root privileges.
0
Attacker Value
Unknown
CVE-2021-33722
Disclosure Date: October 12, 2021 (last updated November 28, 2024)
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system has a Path Traversal vulnerability when exporting a firmware container. With this a privileged authenticated attacker could create arbitrary files on an affected system.
0
Attacker Value
Unknown
CVE-2021-33726
Disclosure Date: October 12, 2021 (last updated November 28, 2024)
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to download arbitrary files under a user controlled path and does not correctly check if the relative path is still within the intended target directory.
0
Attacker Value
Unknown
CVE-2021-33725
Disclosure Date: October 12, 2021 (last updated November 28, 2024)
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to delete arbitrary files or directories under a user controlled path and does not correctly check if the relative path is still within the intended target directory.
0
Attacker Value
Unknown
CVE-2021-33731
Disclosure Date: October 12, 2021 (last updated November 28, 2024)
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.
0