CVE-2024-23811

HIGH

Siemens Sinec Nms < 2.0 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application allows users to upload arbitrary files via TFTP. This could allow an attacker to upload malicious firmware images or other files, that could potentially lead to remote code execution.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0155
EPSS Percentile 81.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (2)
siemens/sinec_nms 2.0
siemens/sinec_nms < 2.0
Published Feb 13, 2024
Tracked Since Feb 18, 2026