CVE-2024-23811

A

vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application allows users to upload arbitrary files via TFTP. This could allow an attacker to upload malicious firmware images or other files, that could potentially lead to remote code execution.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:sinec_nms:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinec_nms:2.0:-:*:*:*:*:*:*

History

21 Nov 2024, 08:58

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/html/ssa-943925.html - Vendor Advisory () https://cert-portal.siemens.com/productcert/html/ssa-943925.html - Vendor Advisory

04 Oct 2024, 16:46

Type Values Removed Values Added
First Time Siemens
Siemens sinec Nms
References () https://cert-portal.siemens.com/productcert/html/ssa-943925.html - () https://cert-portal.siemens.com/productcert/html/ssa-943925.html - Vendor Advisory
CPE cpe:2.3:a:siemens:sinec_nms:2.0:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sinec_nms:*:*:*:*:*:*:*:*

Information

Published : 2024-02-13 09:15

Updated : 2024-11-21 08:58


NVD link : CVE-2024-23811

Mitre link : CVE-2024-23811

CVE.ORG link : CVE-2024-23811


JSON object : View

Products Affected
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type