6.5

CVE-2021-33727

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could download the user profile of any user. With this, the attacker could leak confidential information of any user in the affected system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Siemens ≫ Sinec Nms Version < 1.0
Siemens ≫ Sinec Nms Version 1.0 Update -
Siemens ≫ Sinec Nms Version 1.0 Update sp1
Siemens ≫ Sinec Nms Version 1.0 Update sp2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.85% 0.547
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://cert-portal.siemens.com/productcert/pdf/ssa-163251.pdf
Patch
Vendor Advisory