QID 591313

QID 591313: Siemens SINEC NMS Multiple Vulnerabilities (SSA-250085)

AFFECTED PRODUCTS
SINEC NMS: All versions prior to V1.0.3
SINEC NMS All versions starting from V1.0.3 (only affected by CVE-2022-24282, CVE-2022-25311)

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"

Successful exploitation of these vulnerabilities allows an attacker to execute arbitrary code on the system, arbitrary commands on the local database or achieve privilege escalation.

  • CVSS V3 rated as High - 7.3 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SSA-250085 for affected packages and patching details.

    CVEs related to QID 591313

    Software Advisories
    Advisory ID Software Component Link
    SSA-250085 URL Logo cert-portal.siemens.com/productcert/html/ssa-250085.html