High severity7.2NVD Advisory· Published Aug 10, 2021· Updated Jun 17, 2026
CVE-2021-33721
CVE-2021-33721
Description
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2). The affected application incorrectly neutralizes special elements when creating batch operations which could lead to command injection. An authenticated remote attacker with administrative privileges could exploit this vulnerability to execute arbitrary code on the system with system privileges.
Affected products
5cpe:2.3:a:siemens:sinec_network_management_system:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:siemens:sinec_network_management_system:*:*:*:*:*:*:*:*range: <1.0
- cpe:2.3:a:siemens:sinec_network_management_system:1.0:-:*:*:*:*:*:*
- cpe:2.3:a:siemens:sinec_network_management_system:1.0:sp1:*:*:*:*:*:*
< V1.0 SP2+ 1 more
- (no CPE)range: < V1.0 SP2
- (no CPE)range: All versions < V1.0 SP2
Patches
Vulnerability mechanics
References
1- cert-portal.siemens.com/productcert/pdf/ssa-756744.pdfnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.