QID 591221
Date Published: 2022-12-06
QID 591221: Siemens SINEC NMS and SINEMA Server Multiple Vulnerabilities (SSA-685781 V1.1)
Multiple vulnerabilities were identified in the Apache HTTP Server software. These include NULL Pointer Dereferencing, Out-of-bounds Write and Server-Side Request Forgery related vulnerabilities.
AFFECTED PRODUCTS
The following versions of Siemens SINEC NMS and SINEMA Server, are affected:
SINEC NMS: All versions prior to V1.0.3
SINEMA Server V14
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"
Succesful exploitation of these vulnerabilities affects confidntiality, integrity and availability.
Customers are advised to refer to CERT MITIGATIONS section SSA-685781 for affected packages and patching details.Workaround:
The vendor has advised the following workarounds to reduce risks:
Restrict access to the affected systems, especially to port 443/tcp, to trusted IP addresses only .
CVEs related to QID 591221
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SSA-685781 |
|