QID 590591

Date Published: 2021-11-24

QID 590591: Siemens SINEC NMS Multiple Vulnerabilities (ICSA-21-287-05)

AFFECTED PRODUCTS
The following versions of Siemens SINEC NMS software are affected:
SINEC NMS: Versions prior to v1.0 SP2 Update 1

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"

Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary code on the system, with system privileges, under certain conditions.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-287-05 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-287-05 URL Logo www.us-cert.gov/ics/advisories/ICSA-21-287-05