CVE-2024-47808
- EPSS 0.03%
- Veröffentlicht 12.11.2024 13:15:10
- Zuletzt bearbeitet 13.11.2024 23:14:07
A vulnerability has been identified in SINEC NMS (All versions < V3.0 SP1). The affected application contains a database function, that does not properly restrict the permissions of users to write to the filesystem of the host system. This could all...
CVE-2024-33698
- EPSS 2.84%
- Veröffentlicht 10.09.2024 10:15:09
- Zuletzt bearbeitet 14.10.2025 10:15:34
A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 ...
CVE-2024-41941
- EPSS 0.05%
- Veröffentlicht 13.08.2024 08:15:15
- Zuletzt bearbeitet 14.08.2024 18:12:25
A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This could allow an authenticated attacker to bypass the checks and modify settings in the application wi...
CVE-2024-41940
- EPSS 0.4%
- Veröffentlicht 13.08.2024 08:15:14
- Zuletzt bearbeitet 14.08.2024 18:10:36
A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly validate user input to a privileged command queue. This could allow an authenticated attacker to execute OS commands with elevated priv...
CVE-2024-41939
- EPSS 0.06%
- Veröffentlicht 13.08.2024 08:15:14
- Zuletzt bearbeitet 14.08.2024 18:09:24
A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This could allow an authenticated attacker to bypass the checks and elevate their privileges on the appli...
CVE-2024-41938
- EPSS 0.16%
- Veröffentlicht 13.08.2024 08:15:14
- Zuletzt bearbeitet 14.08.2024 18:08:42
A vulnerability has been identified in SINEC NMS (All versions < V3.0). The importCertificate function of the SINEC NMS Control web application contains a path traversal vulnerability. This could allow an authenticated attacker it to delete arbitrary...
CVE-2024-36398
- EPSS 0.1%
- Veröffentlicht 13.08.2024 08:15:10
- Zuletzt bearbeitet 14.08.2024 18:34:45
A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application executes a subset of its services as `NT AUTHORITY\SYSTEM`. This could allow a local attacker to execute operating system commands with elevated privileg...
CVE-2023-46280
- EPSS 0.04%
- Veröffentlicht 14.05.2024 16:15:40
- Zuletzt bearbeitet 10.12.2024 14:30:35
A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 Upd5), SIMATIC NET PC Software V16 (All versions < V16 Update 8), ...
CVE-2024-31978
- EPSS 0.32%
- Veröffentlicht 09.04.2024 09:15:26
- Zuletzt bearbeitet 21.11.2024 09:14:16
A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP2). Affected devices allow authenticated users to export monitoring data. The corresponding API endpoint is susceptible to path traversal and could allow an authenticated attacke...
CVE-2024-23810
- EPSS 0.76%
- Veröffentlicht 13.02.2024 09:15:49
- Zuletzt bearbeitet 21.11.2024 08:58:28
A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application is vulnerable to SQL injection. This could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the server database.