CVE-2024-23811

HIGH

SINEC NMS < V2.0 SP1 - Unrestricted Upload of File with Dangerous Type via TFTP

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application allows users to upload arbitrary files via TFTP. This could allow an attacker to upload malicious firmware images or other files, that could potentially lead to remote code execution.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0039
EPSS Percentile 30.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (2)
siemens/sinec_nms 2.0
siemens/sinec_nms < 2.0
Published Feb 13, 2024
Tracked Since Feb 18, 2026