CVE-2021-33723

Description

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could change the user profile of any user without proper authorization. With this, the attacker could change the password of any user in the affected system.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.221

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Siemens SINEC NMS *Windows
Multiple Vulnerabilities are affected in Siemens SINEC NMS 1.0Windows
Multiple Vulnerabilities are affected in SINEC NMS *Windows
Multiple Vulnerabilities are affected in SINEC NMS 1.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234