PT-2021-20303 · Siemens · Sinec Nms
Published
2021-10-12
·
Updated
2021-10-18
·
CVE-2021-33728
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
SINEC NMS versions prior to V1.0 SP2 Update 1
Description:
A vulnerability has been identified that allows the upload of JSON objects which are deserialized to JAVA objects. Due to insecure deserialization of user-supplied content, a privileged attacker could exploit this vulnerability by sending a crafted serialized Java object, potentially allowing the execution of arbitrary code on the device with root privileges.
Recommendations:
For versions prior to V1.0 SP2 Update 1, update to V1.0 SP2 Update 1 or later to resolve the issue. As a temporary workaround, consider restricting the upload of JSON objects to trusted sources until a patch is applied.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sinec Nms