CVE-2021-33727

Description

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could download the user profile of any user. With this, the attacker could leak confidential information of any user in the affected system.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.328

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Siemens SINEC NMS *Windows
Multiple Vulnerabilities are affected in Siemens SINEC NMS 1.0Windows
Multiple Vulnerabilities are affected in SINEC NMS *Windows
Multiple Vulnerabilities are affected in SINEC NMS 1.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234