QID 591277
Date Published: 2023-01-12
QID 591277: Siemens SINEC NMS Remote Code Execution (RCE) Vulnerability (SSA-254054)
A vulnerability in Spring Framework was disclosed, that could allow remote unauthenticated attackers to execute code on vulnerable systems. The vulnerability is tracked as CVE-2022-22965 and is also known as Spring4Shell or SpringShell.
AFFECTED PRODUCTS
SINEC NMS: All versions prior to V1.0.3
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"
Successful exploitation of these vulnerabilities affects confidentiality, integrity and availability.
Solution
Customers are advised to refer to CERT MITIGATIONS section SSA-254054 for affected packages and patching details.
Vendor References
CVEs related to QID 591277
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SSA-254054 |
|