VYPR
High severity7.2NVD Advisory· Published Aug 10, 2021· Updated Jun 17, 2026

CVE-2021-33721

CVE-2021-33721

Description

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2). The affected application incorrectly neutralizes special elements when creating batch operations which could lead to command injection. An authenticated remote attacker with administrative privileges could exploit this vulnerability to execute arbitrary code on the system with system privileges.

Affected products

5
  • cpe:2.3:a:siemens:sinec_network_management_system:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:siemens:sinec_network_management_system:*:*:*:*:*:*:*:*range: <1.0
    • cpe:2.3:a:siemens:sinec_network_management_system:1.0:-:*:*:*:*:*:*
    • cpe:2.3:a:siemens:sinec_network_management_system:1.0:sp1:*:*:*:*:*:*
  • Siemens Foundation/Sinec Nmsllm-fuzzy2 versions
    < V1.0 SP2+ 1 more
    • (no CPE)range: < V1.0 SP2
    • (no CPE)range: All versions < V1.0 SP2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.