Vulnerabilities > CVE-2024-23811 - Unspecified vulnerability in Siemens Sinec NMS 1.0/1.0.3/2.0
Attack vector
ADJACENT_NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH low complexity
siemens
Summary
A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application allows users to upload arbitrary files via TFTP. This could allow an attacker to upload malicious firmware images or other files, that could potentially lead to remote code execution.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |