CVE-2024-36398
- EPSS 0.14%
- Veröffentlicht 13.08.2024 08:15:10
- Zuletzt bearbeitet 14.08.2024 18:34:45
A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application executes a subset of its services as `NT AUTHORITY\SYSTEM`. This could allow a local attacker to execute operating system commands with elevated privileg...
CVE-2023-46280
- EPSS 0.05%
- Veröffentlicht 14.05.2024 16:15:40
- Zuletzt bearbeitet 15.04.2026 00:35:42
A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 Upd5), SIMATIC NET PC Software V16 (All versions < V16 Update 8), ...
CVE-2023-6237
- EPSS 0.94%
- Veröffentlicht 25.04.2024 07:15:45
- Zuletzt bearbeitet 12.05.2026 11:16:17
Issue summary: Checking excessively long invalid RSA public keys may take a long time. Impact summary: Applications that use the function EVP_PKEY_public_check() to check RSA public keys may experience long delays. Where the key that is being checke...
CVE-2024-31978
- EPSS 0.18%
- Veröffentlicht 09.04.2024 09:15:26
- Zuletzt bearbeitet 15.04.2026 00:35:42
A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP2). Affected devices allow authenticated users to export monitoring data. The corresponding API endpoint is susceptible to path traversal and could allow an authenticated attacke...
CVE-2024-23812
- EPSS 0.71%
- Veröffentlicht 13.02.2024 09:15:49
- Zuletzt bearbeitet 21.11.2024 08:58:28
A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application incorrectly neutralizes special elements when creating a report which could lead to command injection.
CVE-2024-23811
- EPSS 1.55%
- Veröffentlicht 13.02.2024 09:15:49
- Zuletzt bearbeitet 21.11.2024 08:58:28
A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application allows users to upload arbitrary files via TFTP. This could allow an attacker to upload malicious firmware images or other files, that could potentia...
CVE-2024-23810
- EPSS 0.76%
- Veröffentlicht 13.02.2024 09:15:49
- Zuletzt bearbeitet 21.11.2024 08:58:28
A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application is vulnerable to SQL injection. This could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the server database.
CVE-2023-44487
- EPSS 94.4%
- Veröffentlicht 10.10.2023 14:15:10
- Zuletzt bearbeitet 12.05.2026 15:10:32
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2023-44315
- EPSS 0.47%
- Veröffentlicht 10.10.2023 11:15:12
- Zuletzt bearbeitet 21.11.2024 08:25:39
A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application improperly sanitizes certain SNMP configuration data retrieved from monitored devices. An attacker with access to a monitored device could prepare a stor...
CVE-2022-30527
- EPSS 0.08%
- Veröffentlicht 10.10.2023 11:15:10
- Zuletzt bearbeitet 21.11.2024 07:02:52
A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application assigns improper access rights to specific folders containing executable files and libraries. This could allow an authenticated local attacker to inje...