A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application assigns improper access rights to specific folders containing executable files and libraries.
This could allow an authenticated local attacker to inject arbitrary code and escalate privileges.
References
| Link | Resource |
|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-160243.pdf | Patch Vendor Advisory |
| https://cert-portal.siemens.com/productcert/html/ssa-160243.html |
Configurations
History
09 Jul 2024, 12:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
16 Oct 2023, 18:51
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-10-10 11:15
Updated : 2024-07-09 12:15
NVD link : CVE-2022-30527
Mitre link : CVE-2022-30527
JSON object : View
Products Affected
siemens
- sinec_nms
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
